Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 11 of 26
CVE-2012-3134MEDIUMCVSS 4.0v11.1.0.7v11.2.0.2+1 more2012-07-17
CVE-2012-3134 [MEDIUM] CVE-2012-3134: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2012-1737MEDIUMCVSS 6.8v11.1.0.7v11.2.0.2+1 more2012-07-17
CVE-2012-1737 [MEDIUM] CVE-2012-1737: Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Enterprise Manager Grid Control EM Base Platform 10.2.0.5, EM Base Platform 11.1.0.1, EM Plugin for DB 12.1.0.1, and EM Plugin for DB 12.1.0.2, allows remote attackers to affect confidentiality, integrity, and avail
nvd
CVE-2012-1746MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1746 [MEDIUM] CVE-2012-1746: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2012-1747.
nvd
CVE-2012-1745MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1745 [MEDIUM] CVE-2012-1745: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2012-1747MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1747 [MEDIUM] CVE-2012-1747: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2012-1746.
nvd
CVE-2012-1675HIGHCVSS 7.5PoCv10.2.0.3v10.2.0.4+5 more2012-05-08
CVE-2012-1675 [HIGH] CWE-264 CVE-2012-1675: The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3,
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance
nvd
CVE-2012-0552CRITICALCVSS 9.0v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0552 [CRITICAL] CVE-2012-0552: Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.3, 10.2.0
Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-0519HIGHCVSS 7.1v11.2.0.22012-05-03
CVE-2012-0519 [HIGH] CVE-2012-0519: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when runni
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-0520MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+3 more2012-05-03
CVE-2012-0520 [MEDIUM] CVE-2012-0520: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2, and in Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote attackers to affect integrity via unknown vectors related to Security Framework.
nvd
CVE-2012-0510MEDIUMCVSS 6.4v10.2.0.3v10.2.0.4+2 more2012-05-03
CVE-2012-0510 [MEDIUM] CVE-2012-0510: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, and 11.1.0.7 allows remote attackers to affect integrity and availability via unknown vectors.
nvd
CVE-2012-0527MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0527 [MEDIUM] CVE-2012-0527: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5, allows remote attackers to affect integrity via unknown vectors related to Schema Management, a different vulnerability than CVE-2012-0526.
nvd
CVE-2012-0512MEDIUMCVSS 5.5v11.1.0.7v11.2.0.22012-05-03
CVE-2012-0512 [MEDIUM] CVE-2012-0512: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 11.1.0.7 and 11.2.0.2 and Oracle Enterprise Manager Grid Control allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Enterprise Config Management.
nvd
CVE-2012-0511MEDIUMCVSS 6.4v10.2.0.4v11.1.0.72012-05-03
CVE-2012-0511 [MEDIUM] CVE-2012-0511: Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.
Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2012-0528MEDIUMCVSS 5.8v10.2.0.3v10.2.0.4+2 more2012-05-03
CVE-2012-0528 [MEDIUM] CVE-2012-0528: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, and 11.1.0.7, and Oracle Enterprise Manager Grid Control, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security Framework.
nvd
CVE-2012-0526MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0526 [MEDIUM] CVE-2012-0526: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5, allows remote attackers to affect integrity via unknown vectors related to Schema Management, a different vulnerability than CVE-2012-0527.
nvd
CVE-2012-1708MEDIUMCVSS 4.3v4.0v4.12012-05-03
CVE-2012-1708 [MEDIUM] CVE-2012-1708: Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1
Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2012-0525MEDIUMCVSS 4.9v11.1.0.7v11.2.0.2+1 more2012-05-03
CVE-2012-0525 [MEDIUM] CVE-2012-0525: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Enterprise Config Management.
nvd
CVE-2012-0534MEDIUMCVSS 4.0v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0534 [MEDIUM] CVE-2012-0534: Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 10.2.0.3, 10.2.0.4,
Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Create Session.
nvd
CVE-2012-0072MEDIUMCVSS 5.0v10.1.0.5v10.2.0.3+4 more2012-01-18
CVE-2012-0072 [MEDIUM] CVE-2012-0072: Unspecified vulnerability in the Listener component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10
Unspecified vulnerability in the Listener component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2012-0082MEDIUMCVSS 5.5v10.1.0.5v10.2.0.3+5 more2012-01-18
CVE-2012-0082 [MEDIUM] CVE-2012-0082: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity and availability via unknown vectors.
nvd