Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 28 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.8% | — | Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+8 | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11. | |
| Modificada | Alta (10) | 3.9% | — | Oracle Database ServerOracle10gOracle8iOracle9i | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08. | |
| Modificada | Alta (10) | 3.4% | — | Oracle Database ServerOracle10gOracle8iOracle9i | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable… | |
| Modificada | Alta (7.5) | 4.7% | — | Oracle Database ServerOracle Database Server LiteOracle10gOracle8i+1 | 16/11/2005 | 16/6/2026 | Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username. | |
| Modificada | Alta (8.5) | 6.6% | — | Oracle8iOracle9i | 31/12/2004 | 16/6/2026 | Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument. | |
| Modificada | Media (6.5) | 18% | — | Oracle8iOracle9i | 2/9/2004 | 16/6/2026 | Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible. | |
| Modificada | Media (4.6) | 15% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges. | |
| Modificada | Alta (7.8) | 5.6% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | |
| Modificada | Media (4.6) | 7.4% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user. | |
| Modificada | Alta (9) | 11% | — | Oracle Application ServerOracle Collaboration SuiteOracle Database ServerOracle E-business Suite+6 | 4/8/2004 | 16/6/2026 | Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure. | |
| Modificada | Alta (8.5) | 14% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory. | |
| Modificada | Alta (7.5) | 3.9% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5)… | |
| Modificada | Alta (7.5) | 9.0% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are… | |
| Modificada | Media (5) | 5.6% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory. | |
| Modificada | Media (4.4) | 7.3% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Enterprise Manager+5 | 4/8/2004 | 16/6/2026 | Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM… | |
| Modificada | Alta (7.2) | 2.6% | — | Oracle Application ServerOracle Application Server PortalOracle Database Server LiteOracle8i+1 | 30/7/2004 | 16/6/2026 | The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0. | |
| Modificada | Alta (7.5) | 6.9% | — | Oracle8iOracle9i | 27/8/2003 | 16/6/2026 | Stack-based buffer overflow in the PL/SQL EXTPROC functionality for Oracle9i Database Release 2 and 1, and Oracle 8i, allows authenticated database users, and arbitrary database users in some cases, to execute arbitrary code via a long library name. | |
| Modificada | Alta (9) | 11% | — | Oracle Database ServerOracle8iOracle9i | 12/5/2003 | 16/6/2026 | Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter. | |
| Modificada | Alta (10) | 13% | — | Oracle Database ServerOracle8iOracle9i | 3/3/2003 | 16/6/2026 | Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP. | |
| Modificada | Alta (9) | 16% | — | Oracle Database ServerOracle8iOracle9i | 3/3/2003 | 16/6/2026 | Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the… | |
| Modificada | Media (5) | 3.3% | — | Oracle8iOracle9i | 28/10/2002 | 16/6/2026 | TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command. | |
| Modificada | Alta (7.5) | 21% | — | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i | 11/10/2002 | 16/6/2026 | Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response. | |
| Modificada | Media (6.8) | 95% | — | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i+1 | 11/10/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than… | |
| Modificada | Alta (7.5) | 14% | — | Oracle Database ServerOracle8i | 5/9/2002 | 16/6/2026 | Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file. | |
| Modificada | Alta (7.5) | 2.2% | — | Oracle8iOracle9i | 5/9/2002 | 16/6/2026 | catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges. |