cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 13 of 26
CVE-2014-6477P4MEDIUMCVSS 6.8v11.1.0.7v11.2.0.3+3 more2014-11-23
CVE-2014-6477 [MEDIUM] CVE-2014-6477: Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4293, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, and CVE-2014
nvd
CVE-2011-0835P4MEDIUMCVSS 6.5v11.1.0.7v11.2.0.1+1 more2011-07-20
CVE-2011-0835 [MEDIUM] CVE-2011-0835: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2011-0832 and CVE-2011-0880.
nvd
CVE-2011-0880P4MEDIUMCVSS 6.5v11.1.0.7v11.2.0.1+1 more2011-07-20
CVE-2011-0880 [MEDIUM] CVE-2011-0880: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2011-0832 and CVE-2011-0835.
nvd
CVE-2004-1339P4MEDIUMCVSS 6.5v10.2.12004-12-23
CVE-2004-1339 [MEDIUM] CWE-89 CVE-2004-1339: SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS defau SQL injection vulnerability in the (1) MDSYS.SDO_GEOM_TRIG_INS1 and (2) MDSYS.SDO_LRS_TRIG_INS default triggers in Oracle 9i and 10g allows remote attackers to execute arbitrary SQL commands via the new.table_name or new.column_name parameters.
nvd
CVE-2011-0792P4MEDIUMCVSS 6.5v11.1.0.7v10.2.0.52011-04-20
CVE-2011-0792 [MEDIUM] CVE-2011-0792: Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0 Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0.5 (OWB) and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Dimensional Data Modeling.
nvd
CVE-2006-1872P4HIGHCVSS 7.5v9.0.1.5v9.2.0.72006-04-20
CVE-2006-1872 [HIGH] CVE-2006-1872: Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attac Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.
nvd
CVE-2005-3443P4CRITICALCVSS 10.0v9.2.0.5v9.2.0.6+2 more2005-11-02
CVE-2005-3443 [CRITICAL] CVE-2005-3443: Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB17.
nvd
CVE-2015-4740P4MEDIUMCVSS 6.0v11.1.0.7v11.2.0.3+3 more2015-07-16
CVE-2015-4740 [MEDIUM] CVE-2015-4740: Unspecified vulnerability in the RDBMS Partitioning component in Oracle Database Server 11.1.0.7, 11 Unspecified vulnerability in the RDBMS Partitioning component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2015-0468P4MEDIUMCVSS 6.0v11.1.0.7v11.2.0.3+1 more2015-07-16
CVE-2015-0468 [MEDIUM] CVE-2015-0468: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-0528P4MEDIUMCVSS 5.8v10.2.0.3v10.2.0.4+2 more2012-05-03
CVE-2012-0528 [MEDIUM] CVE-2012-0528: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, and 11.1.0.7, and Oracle Enterprise Manager Grid Control, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security Framework.
nvd
CVE-2006-5340P4HIGHCVSS 7.1v8.1.7.4v9.0.1.5+3 more2006-10-18
CVE-2006-5340 [HIGH] CVE-2006-5340: Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5 Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related
nvd
CVE-2022-21606P4MEDIUMCVSS 6.1v19c2022-10-18
CVE-2022-21606 [MEDIUM] CWE-79 CVE-2022-21606: Vulnerability in the Oracle Services for Microsoft Transaction Server component of Oracle Database S Vulnerability in the Oracle Services for Microsoft Transaction Server component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Services for Microsoft Transaction Server. Successful attacks require human interac
nvd
CVE-2007-5512P4HIGHCVSS 7.5v9.2.0.8dvv10.2.0.32007-10-17
CVE-2007-5512 [HIGH] CVE-2007-5512: Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV and 10 Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV and 10.2.0.3 has unknown impact and remote attack vectors, aka DB21.
nvd
CVE-2007-0270P4MEDIUMCVSS 6.5v9.2.0.7v10.1.0.42007-01-17
CVE-2007-0270 [MEDIUM] CWE-119 CVE-2007-0270: Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.
nvd
CVE-2007-2119P4MEDIUMCVSS 6.8v9.2.0.8v10.1.0.5+1 more2007-04-18
CVE-2007-2119 [MEDIUM] CVE-2007-2119: Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for O Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.
nvd
CVE-2007-0271P4MEDIUMCVSS 6.5v9.0.1.5v9.2.0.72007-01-17
CVE-2007-0271 [MEDIUM] CVE-2007-0271: Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vecto Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.
nvd
CVE-2021-2234P4MEDIUMCVSS 5.3v12.1.0.2v12.2.0.1+2 more2021-04-22
CVE-2021-2234 [MEDIUM] CVE-2021-2234: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2007-2112P4MEDIUMCVSS 6.0v10.1.0.5v10.2.0.32007-04-18
CVE-2007-2112 [MEDIUM] CVE-2007-2112: Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and attack vectors, aka DB05. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue allows remote authenticated users to bypass the AUTH_ALTER_SESSION security policies via a logon trigger ("AFTER LOGON ON DATABASE" tri
nvd
CVE-2011-0838P4MEDIUMCVSS 6.5v11.1.0.7v11.2.0.1+1 more2011-07-20
CVE-2011-0838 [MEDIUM] CVE-2011-0838: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to create procedure privileges.
nvd
CVE-2012-1751P4MEDIUMCVSS 6.5v11.1.0.7v11.2.0.2+1 more2012-10-16
CVE-2012-1751 [MEDIUM] CVE-2012-1751: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to flashback archive.
nvd
Oracle Database Server vulnerabilities | cvebase