Oracle Database Server vulnerabilities

502 known vulnerabilities affecting oracle/database_server.

Total CVEs
502
CISA KEV
0
Public exploits
25
Exploited in wild
0
Severity breakdown
CRITICAL112HIGH71MEDIUM250LOW69

Vulnerabilities

Page 10 of 26
CVE-2013-3751CRITICALCVSS 9.0v11.2.0.2v11.2.0.32013-07-17
CVE-2013-3751 [CRITICAL] CVE-2013-3751: Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3, Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-3771HIGHCVSS 7.2v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3771 [HIGH] CVE-2013-3771: Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10. Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-3760.
nvd
CVE-2013-3774HIGHCVSS 7.6v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3774 [HIGH] CVE-2013-3774: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0. Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-3760HIGHCVSS 7.2v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3760 [HIGH] CVE-2013-3760: Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10. Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-3771.
nvd
CVE-2013-3789MEDIUMCVSS 6.5v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3789 [MEDIUM] CVE-2013-3789: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-3790LOWCVSS 2.1v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3790 [LOW] CVE-2013-3790: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Privileged Account.
nvd
CVE-2013-1534CRITICALCVSS 10.0v11.2.0.2v11.2.0.32013-04-17
CVE-2013-1534 [CRITICAL] CVE-2013-1534: Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 1 Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-1554MEDIUMCVSS 5.0v10.2.0.4v10.2.0.5+3 more2013-04-17
CVE-2013-1554 [MEDIUM] CVE-2013-1554: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0. Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2013-1519MEDIUMCVSS 5.0v4.2.12013-04-17
CVE-2013-1519 [MEDIUM] CVE-2013-1519: Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2. Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2013-1538MEDIUMCVSS 5.0v11.2.0.2v11.2.0.32013-04-17
CVE-2013-1538 [MEDIUM] CVE-2013-1538: Unspecified vulnerability in the Network Layer component in Oracle Database Server 11.2.0.2 and 11.2 Unspecified vulnerability in the Network Layer component in Oracle Database Server 11.2.0.2 and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2012-3220CRITICALCVSS 9.0v10.2.0.3v10.2.0.4+4 more2013-01-17
CVE-2012-3220 [CRITICAL] CVE-2012-3220: Unspecified vulnerability in the Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10. Unspecified vulnerability in the Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users with Create Session privileges to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-1751MEDIUMCVSS 6.5v11.1.0.7v11.2.0.2+1 more2012-10-16
CVE-2012-1751 [MEDIUM] CVE-2012-1751: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to flashback archive.
nvd
CVE-2012-3146LOWCVSS 2.1v10.2.0.3v10.2.0.4+4 more2012-10-16
CVE-2012-3146 [LOW] CVE-2012-3146: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2012-3151LOWCVSS 3.3v10.2.0.4v10.2.0.5+3 more2012-10-16
CVE-2012-3151 [LOW] CVE-2012-3151: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Unix and Linux platforms, allows local users to affect integrity and availability via unknown vectors.
nvd
CVE-2012-3137MEDIUMCVSS 6.4PoCv10.2.0.3v10.2.0.4+4 more2012-09-21
CVE-2012-3137 [MEDIUM] CWE-287 CVE-2012-3137: The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0 The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vu
nvd
CVE-2012-3132MEDIUMCVSS 6.5v10.2.0.3v10.2.0.4+4 more2012-08-10
CVE-2012-3132 [MEDIUM] CWE-89 CVE-2012-3132: SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0 SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.
nvd
CVE-2012-3134MEDIUMCVSS 4.0v11.1.0.7v11.2.0.2+1 more2012-07-17
CVE-2012-3134 [MEDIUM] CVE-2012-3134: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2012-1737MEDIUMCVSS 6.8v11.1.0.7v11.2.0.2+1 more2012-07-17
CVE-2012-1737 [MEDIUM] CVE-2012-1737: Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Enterprise Manager Grid Control EM Base Platform 10.2.0.5, EM Base Platform 11.1.0.1, EM Plugin for DB 12.1.0.1, and EM Plugin for DB 12.1.0.2, allows remote attackers to affect confidentiality, integrity, and avail
nvd
CVE-2012-1746MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1746 [MEDIUM] CVE-2012-1746: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0. Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2012-1747.
nvd
CVE-2012-1745MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1745 [MEDIUM] CVE-2012-1745: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0. Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd