cbcvebase.
CVE-2003-0095
published 2003-03-03

CVE-2003-0095: Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is…

PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
13.11%
95.9th percentile
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.

Affected

10 ranges
VendorProductVersion rangeFixed in
oracledatabase_server
oracledatabase_server
oracledatabase_server
oracleoracle8i
oracleoracle8i
oracleoracle9i
oracleoracle9i
oracleoracle9i
oracleoracle9i
oracleoracle9i
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.