VYPR

TNS Listener

by Oracle Corporation

CVEs (4)

  • CVE-2002-0965Oct 4, 2002
    risk 0.09cvss epss 0.70

    Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.

  • CVE-2000-0169Mar 15, 2000
    risk 0.05cvss epss 0.27

    Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.

  • CVE-2007-5507Oct 17, 2007
    risk 0.00cvss epss 0.03

    The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (crash) or read potentially sensitive memory via a connect GIOP packet with an…

  • CVE-2000-0818Dec 19, 2000
    risk 0.00cvss epss 0.05

    The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.