CVE Database
/

CVE-2002-0559

Back to search

CVE-2002-0559

Published: Jun 11, 2002

Modified: Aug 8, 2024

PUBLISHED

Description

Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#750299
third-party-advisory
x_refsource_CERT-VN
VU#878603
third-party-advisory
x_refsource_CERT-VN
CA-2002-08
third-party-advisory
x_refsource_CERT
VU#659043
third-party-advisory
x_refsource_CERT-VN
VU#313280
third-party-advisory
x_refsource_CERT-VN
4032
vdb-entry
x_refsource_BID
oracle-appserver-plsql-bo(8095)
vdb-entry
x_refsource_XF
VU#923395
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now