CVE-2007-1442Oracle Database Server vulnerability

5 documents5 sources
Severity
7.2HIGHNVD
EPSS
0.7%
top 26.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 1

Description

Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDoracle/database_server10.2.1, 10.2.2, 10.2.3+2

🔴Vulnerability Details

2
GHSA
GHSA-7w8h-97qm-v5g3: Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACL2022-05-01
CVEList
CVE-2007-1442: Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACL2007-03-14

💥Exploits & PoCs

1
Exploit-DB
VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String2008-04-28

💬Community

1
Bugzilla
CVE-2007-4974 Heap overflow in libsndfile triggerable by seeks2008-01-28
CVE-2007-1442 — Oracle Database Server vulnerability | cvebase