|
CVE-2004-2115
|
Medium
|
2004-12-31
|
Mitigation candidate
|
Working exploit published
|
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
|
|
CVE-2004-1364
|
High
|
2004-08-04
|
Protected by RASP
|
Working exploit published
|
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
|
|
CVE-2004-0095
|
Medium
|
2004-02-17
|
Mitigation candidate
|
Working exploit published
|
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
|