<?xml version="1.0" encoding="Windows-1252"?>
<rss version="2.0">
	<channel>
	<title>Published Security Alerts</title>
	<pubDate>9 Jan 2006 13:00:00 GMT</pubDate>
	<link>http://www.red-database-security.com/advisory/published_alerts.html</link>
	<description>Published Security Alerts</description>
	<language>en-us</language>
		<item>	  
  <title>SQL Injection in SYS.KUPV$FT in Oracle 10g. Rel. 1</title>
  <pubDate>17 Jan 2006 18:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html</link>
  </item>
  <item>	  
  <title>SQL Injection in SYS.KUPV$FT_INT in Oracle 10g. Rel. 1</title>
  <pubDate>17 Jan 2006 18:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html</link>
  </item>
	<item>	  
  <title>Event 10053 logs TDE wallet password in cleartext</title>
  <pubDate>17 Jan 2006 13:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html</link>
  </item>
  <item>	  
  <title>Transparent Data Encryption stores key unencrypted in the SGA</title>
  <pubDate>17 Jan 2006 13:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html</link>
  </item>
	<item>	  
  <title>Cross-Site-Scripting in Oracle Workflow wf_route</title>
  <pubDate>20 Oct 2005 13:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_workflow_css_wf_route.html</link>
  </item>
  <item> 
  <title>Cross-Site-Scripting in Oracle Workflow wf_monitor</title>
  <pubDate>20 Oct 2005 13:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_workflow_css_wf_monitor.html</link>
  </item>
  <item> 
  <title>Shutdown listener via iSQL*Plus</title>
  <pubDate>7 Oct 2005 13:00:00 GMT</pubDate>
  <link>http://www.red-database-security.com/advisory/oracle_isqlplus_shutdown.html</link>
  </item>
  <item>
 <title>Shutdown listener via Forms Servlet</title>
<pubDate>7 Oct 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_forms_shutdown.html</link>
</item>
<item>
<title>Plaintext Passwords logged during Installation of Oracle HTMLDB</title>
<pubDate>7 Oct 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_htmldb_plaintext_password.html</link>
</item>
<item>
<title>Cross-Site-Scripting Vulnerabilities in Oracle HTMLDB</title>
<pubDate>7 Oct 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_htmldb_css.html</link>
</item>
<item>
<title>Cross-Site-Scripting Vulnerabilities in Oracle iSQL*Plus</title>
<pubDate>7 Oct 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_isqlplus_css.html</link>
</item>
<item>
<title>Cross-Site-Scripting Vulnerabilities in Oracle XMLDB</title>
<pubDate>7 Oct 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_xmldb_css.html</link>
</item>
<item>
<title>Various Cross-Site-Scripting Vulnerabilities in Oracle Report</title>
<pubDate>19 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_reports_various_css.html</link>
</item>
<item>
<title>Read parts of any XML-file on the application server via Oracle Report</title>
<pubDate>19 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html</link>
</item>
<item>
<title>Read parts of any file on the application server via Oracle Report</title>
<pubDate>19 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html</link>
</item>
<item>
<title>Overwrite any file on the application server via Oracle Report</title>
<pubDate>19 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html</link>
</item>
<item>
<title>Run any OS Command via uploaded Oracle Report from any directory</title>
<pubDate>19 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_reports_run_any_os_command.html</link>
</item>
<item>
<title>Run any OS Command via uploaded Oracle Forms from any directory</title>
<pubDate>19 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_forms_run_any_os_command.html</link>
</item>
<item>
<title>Oracle JDeveloper passes plaintext password</title>
<pubDate>12 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_jdeveloper_passes_plaintext_password.html</link>
</item>
<item>
<title>Plaintext password in Oracle JDeveloper</title>
<pubDate>12 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_jdeveloper_plaintext_password.html</link>
</item>
<item>
<title>Unsecure temp file handling in Oracle Formsbuilder</title>
<pubDate>12 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_formsbuilder_temp_file_issue.html</link>
</item>
<item>
<title>Unsecure temp file handling in Oracle Forms</title>
<pubDate>12 Jul 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.html</link>
</item>
<item>
<title>Fine Grained Auditing issue  in Oracle 9i / 10g</title>
<pubDate>02 May 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle-fine-grained-auditing-issue.html</link>
</item>
<item>
<title>DBMS_SCHEDULER 10g SELECT user issue in Oracle 10g</title>
<pubDate>02 May 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/exploits/oracle_exploit_dbms_scheduler_select_user.html</link>
</item>
<item> 
<title>Webcache Client Requests bypasses OHS mod_access Restrictions</title>
<pubDate>26 Apr 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_webcache_bypass.html</link>
</item>
<item> 
 	<title>File append vulnerability in Webcache Admin Console</title>
<pubDate>26 Apr 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html</link>
</item>
<item>			
	<title>CSS in Webcache Admin Console</title>
<pubDate>26 Apr 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_webcache_CSS_vulnerabilities.html</link>
</item>
<item>
	<title>CSS in BEA admin console</title>
<pubDate>25 Apr 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/bea_css_in_admin_console.html</link>
</item>
<item>
	<title>SQL Injection in Oracle Forms</title>
<pubDate>12 Apr 2005 13:00:00 GMT</pubDate>
			<link>http://www.red-database-security.com/wp/sql_injection_forms_us.pdf</link>
</item>
<item>
<title>Buffer Overflow in Create Database Link in Oracle8i - 9i</title>
<pubDate>18 Jan 2005 13:00:00 GMT</pubDate>
<link>http://www.red-database-security.com/advisory/oracle_buffer_overflow_in_create_database_link.html</link>
</item>

	</channel>
	</rss>