CVE Vulnerabilities

CVE-2004-0385

Published: Jun 01, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple vulnerabilities.

Affected Software

NameVendorStart VersionEnd Version
Application_server_web_cacheOracle9.0.0.4.0 (including)9.0.0.4.0 (including)
Application_server_web_cacheOracle9.0.2.3.0 (including)9.0.2.3.0 (including)
Application_server_web_cacheOracle9.0.3.1.0 (including)9.0.3.1.0 (including)
Application_server_web_cacheOracle9.0.4.0.0 (including)9.0.4.0.0 (including)
E-business_suiteOracle11i (including)11i (including)

References