CVE-2004-1363
published 2004-08-04CVE-2004-1363: Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded…
PriorityP335critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
9.10%
94.7th percentile
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Incorrect Calculation of Buffer Size
mitre_cwe
CWE-131 Incorrect Calculation of Buffer Size
CWE-131: Incorrect Calculation of Buffer Size
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Availability, Confidentiality. Impact: DoS: Crash, Exit, or Restart, Execute Unauthorized Code or Commands, Read Memory, Modify Memory. If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing arbitrary code execution, or exposing sensitive data.
Detection Methods:
Automated Static Analysis: This
CWE
Incorrect Calculation
mitre_cwe
CWE-682 Incorrect Calculation
CWE-682: Incorrect Calculation
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
When product performs a security-critical calculation incorrectly, it might lead to incorrect resource allocations, incorrect privilege assignments, or failed comparisons among other things. Many of the direct results of an incorrect calculation can lead to even larger problems such as failed protection mechanisms or even arbitrary code execution.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. If the incorrect calculation causes the program to move into an unexpected state, it may lead to a crash or impairment of service.
Sc
http://marc.info/?l=bugtraq&m=110382345829397&w=2http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1http://www.kb.cert.org/vuls/id/316206http://www.ngssoftware.com/advisories/oracle23122004.txthttp://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://www.securityfocus.com/bid/10871http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18659http://marc.info/?l=bugtraq&m=110382345829397&w=2http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1http://www.kb.cert.org/vuls/id/316206http://www.ngssoftware.com/advisories/oracle23122004.txthttp://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://www.securityfocus.com/bid/10871http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/18659
2004-08-04
Published