Oracle / Reports
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2005-2983 | SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the param… | HIGH | 7.5 | Sep 19, 2005 |
| CVE-2005-2379 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug par… | MEDIUM | 4.3 | Jul 26, 2005 |
| CVE-2005-2378 | Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2… | MEDIUM | 5.0 | Jul 26, 2005 |
| CVE-2005-2371 | Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive l… | MEDIUM | 5.0 | Jul 26, 2005 |
| CVE-2002-0947 | Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to e… | HIGH | 7.5 | Apr 2, 2003 |
| CVE-2002-1089 | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use t… | MEDIUM | 5.0 | Aug 31, 2002 |
Showing 1 to 6 of 6 CVEs