CVE-2004-1774
published 2004-08-31CVE-2004-1774: Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
2.67%
84.1th percentile
Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | oracle10g | — | — |
| oracle | oracle10g | — | — |
| oracle | oracle10g | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/025984.htmlhttp://www.appsecinc.com/resources/alerts/oracle/2004-0001/http://www.frsirt.com/exploits/20050413.OracleExploit.sql.phphttp://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://www.securiteam.com/securitynews/5CP010KE0W.htmlhttp://www.securityfocus.com/bid/13145https://exchange.xforce.ibmcloud.com/vulnerabilities/20078http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/025984.htmlhttp://www.appsecinc.com/resources/alerts/oracle/2004-0001/http://www.frsirt.com/exploits/20050413.OracleExploit.sql.phphttp://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfhttp://www.securiteam.com/securitynews/5CP010KE0W.htmlhttp://www.securityfocus.com/bid/13145https://exchange.xforce.ibmcloud.com/vulnerabilities/20078
2004-08-31
Published