AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2005-2371

MEDIUM · CVSS 5 EPSS 22.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-07-26 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2005-2371
Severity
MEDIUM
CVSS
5
EPSS
22.29%
Windows Oracle

Original Filing — NVD Description

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.