Oracle Database Server vulnerabilities

502 known vulnerabilities affecting oracle/database_server.

Total CVEs
502
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL112HIGH71MEDIUM250LOW69

Vulnerabilities

Page 14 of 26
CVE-2010-4421MEDIUMCVSS 6.8v10.2.0.3v10.2.0.4+3 more2011-01-19
CVE-2010-4421 [MEDIUM] CVE-2010-4421: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0 Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-4413MEDIUMCVSS 4.3v11.1.0.7v11.2.0.12011-01-19
CVE-2010-4413 [MEDIUM] CVE-2010-4413: Unspecified vulnerability in the Scheduler Agent component in Oracle Database Server 11.1.0.7 and 11 Unspecified vulnerability in the Scheduler Agent component in Oracle Database Server 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-3590MEDIUMCVSS 4.9v10.2.0.4v11.1.0.7+1 more2011-01-19
CVE-2010-3590 [MEDIUM] CVE-2010-3590: Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.4, 11.1.0 Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality and integrity, related to MDSYS.
nvd
CVE-2010-4423MEDIUMCVSS 6.9v10.2.0.4v10.2.0.5+1 more2011-01-19
CVE-2010-4423 [MEDIUM] CVE-2010-4423: Unspecified vulnerability in the Cluster Verify Utility component in Oracle Database Server 10.2.0.4 Unspecified vulnerability in the Cluster Verify Utility component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-4420LOWCVSS 3.6v10.2.0.3v10.2.0.4+3 more2011-01-19
CVE-2010-4420 [LOW] CVE-2010-4420: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0 Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows local users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2010-2390HIGHCVSS 7.5v10.1.0.5v10.2.0.32010-10-14
CVE-2010-2390 [HIGH] CVE-2010-2390: Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-2412MEDIUMCVSS 5.5v11.1.0.72010-10-14
CVE-2010-2412 [MEDIUM] CVE-2010-2412: Unspecified vulnerability in the OLAP component in Oracle Database Server 11.1.0.7 allows remote aut Unspecified vulnerability in the OLAP component in Oracle Database Server 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2010-2415MEDIUMCVSS 4.9PoCv10.1.0.5v10.2.0.4+2 more2010-10-14
CVE-2010-2415 [MEDIUM] CVE-2010-2415: Unspecified vulnerability in the Change Data Capture component in Oracle Database Server 10.1.0.5, 1 Unspecified vulnerability in the Change Data Capture component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_CDC_PUBLISH.
nvd
CVE-2010-2407MEDIUMCVSS 4.3v10.1.0.5v10.2.0.4+1 more2010-10-14
CVE-2010-2407 [MEDIUM] CVE-2010-2407: Unspecified vulnerability in the XDK component in Oracle Database Server 10.1.0.5, 10.2.0.4, and 11. Unspecified vulnerability in the XDK component in Oracle Database Server 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2010-2411MEDIUMCVSS 4.6v10.1.0.5v10.2.0.3+3 more2010-10-14
CVE-2010-2411 [MEDIUM] CVE-2010-2411: Unspecified vulnerability in the Job Queue component in Oracle Database Server 11.2.0.1, 11.1.0.7, 1 Unspecified vulnerability in the Job Queue component in Oracle Database Server 11.2.0.1, 11.1.0.7, 10.2.0.3, 10.2.0.4, and 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DBMS_IJOB.
nvd
CVE-2010-2419MEDIUMCVSS 6.5v10.1.0.5v10.2.0.4+2 more2010-10-14
CVE-2010-2419 [MEDIUM] CVE-2010-2419: Unspecified vulnerability in the Java Virtual Machine component in Oracle Database Server 10.1.0.5, Unspecified vulnerability in the Java Virtual Machine component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-2389LOWCVSS 1.0v10.1.0.5v10.2.0.3+3 more2010-10-14
CVE-2010-2389 [LOW] CVE-2010-2389: Unspecified vulnerability in the Perl component in Oracle Database Server 11.2.0.1, 11.1.0.7, 10.2.0 Unspecified vulnerability in the Perl component in Oracle Database Server 11.2.0.1, 11.1.0.7, 10.2.0.3, 10.2.0.4, and 10.1.0.5; and Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0; allows local users to affect integrity via unknown vectors related to Local Logon.
nvd
CVE-2010-2391LOWCVSS 3.6v10.1.0.5v10.2.0.32010-10-14
CVE-2010-2391 [LOW] CVE-2010-2391: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5 and 10.2.0. Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2010-0911HIGHCVSS 7.8v9.2.0.8v9.2.0.8dv+4 more2010-07-13
CVE-2010-0911 [HIGH] CVE-2010-0911: Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10 Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-0903HIGHCVSS 7.8v9.2.0.8v10.1.0.5+3 more2010-07-13
CVE-2010-0903 [HIGH] CVE-2010-0903: Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 1 Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-0892MEDIUMCVSS 4.3v3.2.0.00.272010-07-13
CVE-2010-0892 [MEDIUM] CVE-2010-0892: Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2.0.00.27 Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2.0.00.27 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2010-0902MEDIUMCVSS 6.0v9.2.0.8v9.2.0.8dv+4 more2010-07-13
CVE-2010-0902 [MEDIUM] CVE-2010-0902: Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0900LOWCVSS 2.6v9.2.0.8v10.1.0.5+3 more2010-07-13
CVE-2010-0900 [LOW] CVE-2010-0900: Unspecified vulnerability in the Network Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5 Unspecified vulnerability in the Network Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-0901LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+4 more2010-07-13
CVE-2010-0901 [LOW] CVE-2010-0901: Unspecified vulnerability in the Export component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1 Unspecified vulnerability in the Export component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Select Any Dictionary.
nvd
CVE-2010-0853HIGHCVSS 7.5v9.2.0.8v9.2.0.8dv2010-04-13
CVE-2010-0853 [HIGH] CVE-2010-0853: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2 Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2.0.8, and DV; and Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd