CVE-2004-1363Incorrect Calculation of Buffer Size in Oracle Application Server

Severity
9.8CRITICALNVD
EPSS
27.7%
top 3.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4
Latest updateApr 29

Description

Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v25x-3wqw-87r9: Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are ex2022-04-29
CVEList
CVE-2004-1363: Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are ex2005-01-19
CVE-2004-1363 — Incorrect Calculation of Buffer Size | cvebase