Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 1 of 26
CVE-2009-1979P2CRITICALCVSS 10.0PoCv10.1.0.5v10.2.0.42009-10-22
CVE-2009-1979 [CRITICAL] CVE-2009-1979: Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is re
nvd
CVE-2012-1675P2HIGHCVSS 7.5PoCv10.2.0.3v10.2.0.4+5 more2012-05-08
CVE-2012-1675 [HIGH] CWE-264 CVE-2012-1675: The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3,
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance
nvd
CVE-2010-3600P2HIGHCVSS 7.5PoCv11.1.0.7v11.2.0.12011-01-19
CVE-2010-3600 [HIGH] CVE-2010-3600: Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claim
nvd
CVE-2012-3137P2MEDIUMCVSS 6.4PoCv10.2.0.3v10.2.0.4+4 more2012-09-21
CVE-2012-3137 [MEDIUM] CWE-287 CVE-2012-3137: The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vu
nvd
CVE-2010-0071P2CRITICALCVSS 10.0PoCv9.2.0.8v9.2.0.8dv+3 more2010-01-13
CVE-2010-0071 [CRITICAL] CVE-2010-0071: Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1019P3HIGHCVSS 7.5PoCv9.2.0.8v9.2.0.8dv+3 more2009-07-14
CVE-2009-1019 [HIGH] CVE-2009-1019: Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1020P3CRITICALCVSS 9.0PoCv9.2.0.8v9.2.0.8dv+3 more2009-07-14
CVE-2009-1020 [CRITICAL] CVE-2009-1020: Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV,
Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-0287P3CRITICALCVSS 10.0PoCv10.1.0.52006-01-18
CVE-2006-0287 [CRITICAL] CVE-2006-0287: Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.
nvd
CVE-2008-0339P3CRITICALCVSS 10.0PoCv9.2.0.8dvv10.1.0.5+1 more2008-01-17
CVE-2008-0339 [CRITICAL] CVE-2008-0339: Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, a
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.
nvd
CVE-2009-1963P3HIGHCVSS 7.5PoCv11.1.0.62009-07-14
CVE-2009-1963 [HIGH] CVE-2009-1963: Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows rem
Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and availability via unknown vectors.
nvd
CVE-2006-3698P3CRITICALCVSS 10.0PoCv10.1.0.52006-07-21
CVE-2006-3698 [CRITICAL] CVE-2006-3698: Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vect
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB01 is related to multiple SQL injection vulnerabilities in SY
nvd
CVE-2002-0840P4MEDIUMCVSS 6.8PoCv8.1.7v9.2.1+1 more2002-10-11
CVE-2002-0840 [MEDIUM] CVE-2002-0840: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
nvd
CVE-2010-0866P3MEDIUMCVSS 6.5PoCv11.1.0.7v11.2.0.12010-04-13
CVE-2010-0866 [MEDIUM] CVE-2010-0866: Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows re
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-0549P3HIGHCVSS 7.5PoCv10.1.0.52006-02-04
CVE-2006-0549 [HIGH] CVE-2006-0549: SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possib
SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has
nvd
CVE-2020-1953P2CRITICALCVSS 10.0v11.2.0.4v12.1.0.2+3 more2020-03-13
CVE-2020-1953 [CRITICAL] CVE-2020-1953: Apache Commons Configuration uses a third-party library to parse YAML files which by default allows
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could therefore l
nvd
CVE-2007-3855P3MEDIUMCVSS 6.5PoCv9.0.1.5v9.2.0.8+3 more2007-07-18
CVE-2007-3855 [MEDIUM] CVE-2007-3855: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17). N
nvd
CVE-2018-14719P2CRITICALCVSS 9.8v11.2.0.4v12.1.0.2+3 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2017-15095P2CRITICALCVSS 9.8v12.2.0.1v18.12018-02-06
CVE-2017-15095 [CRITICAL] CWE-184 CVE-2017-15095: A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, w
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be us
nvd
CVE-2009-1968P3MEDIUMCVSS 4.3PoCv10.1.8.32009-07-14
CVE-2009-1968 [MEDIUM] CVE-2009-1968: Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allo
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups pa
nvd
CVE-2026-46833P2CRITICALCVSS 9.0≥ 23.4.0, ≤ 23.26.22026-05-28
CVE-2026-46833 [CRITICAL] CVE-2026-46833: Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are a
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change
nvd
1 / 26Next →