CVE Vulnerabilities

CVE-2004-0385

Published: Jun 01, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple vulnerabilities.

Affected Software

Name Vendor Start Version End Version
Application_server_web_cache Oracle 9.0.0.4.0 (including) 9.0.0.4.0 (including)
Application_server_web_cache Oracle 9.0.2.3.0 (including) 9.0.2.3.0 (including)
Application_server_web_cache Oracle 9.0.3.1.0 (including) 9.0.3.1.0 (including)
Application_server_web_cache Oracle 9.0.4.0.0 (including) 9.0.4.0.0 (including)
E-business_suite Oracle 11i (including) 11i (including)

References