Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 15 of 26
CVE-2011-0832P4MEDIUMCVSS 6.0v11.1.0.7v11.2.0.1+1 more2011-07-20
CVE-2011-0832 [MEDIUM] CVE-2011-0832: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2011-0835 and CVE-2011-0880.
nvd
CVE-2011-2232P4MEDIUMCVSS 6.0v10.1.0.5v10.2.0.3+3 more2011-07-20
CVE-2011-2232 [MEDIUM] CVE-2011-2232: Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.
Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7, and 11.2.0.1, and Oracle Fusion Middleware 10.1.3.5, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2007-3854P4MEDIUMCVSS 5.5v9.0.1.5v9.2.0.7+5 more2007-07-18
CVE-2007-3854 [MEDIUM] CVE-2007-3854: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is
nvd
CVE-2009-1018P4MEDIUMCVSS 5.5v10.2.0.42009-10-22
CVE-2009-1018 [MEDIUM] CVE-2009-1018: Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remo
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC).
nvd
CVE-2009-1964P4MEDIUMCVSS 5.5v10.2.0.42009-10-22
CVE-2009-1964 [MEDIUM] CVE-2009-1964: Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remo
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2011-0875P4MEDIUMCVSS 5.5v11.1.0.72011-07-20
CVE-2011-0875 [MEDIUM] CVE-2011-0875: Unspecified vulnerability in the EMCTL component in Oracle Database Server 11.1.0.7 and Oracle Enter
Unspecified vulnerability in the EMCTL component in Oracle Database Server 11.1.0.7 and Oracle Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-1993P4MEDIUMCVSS 5.5v3.0.12009-10-22
CVE-2009-1993 [MEDIUM] CVE-2009-1993: Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remot
Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remote authenticated users to affect confidentiality and integrity, related to FLOWS_030000.WWV_EXECUTE_IMMEDIATE.
nvd
CVE-2012-0082P4MEDIUMCVSS 5.5v10.1.0.5v10.2.0.3+5 more2012-01-18
CVE-2012-0082 [MEDIUM] CVE-2012-0082: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity and availability via unknown vectors.
nvd
CVE-2008-1816P4MEDIUMCVSS 5.5v10.1.0.5v10.2.0.32008-04-16
CVE-2008-1816 [MEDIUM] CVE-2008-1816: Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact an
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) SDO_UTIL in the Oracle Spatial component, aka DB05; or (2) fine grained auditing in the Audit component, aka DB14. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on
nvd
CVE-2008-2592P4MEDIUMCVSS 5.5v9.2.0.8v10.1.0.52008-07-15
CVE-2008-2592 [MEDIUM] CVE-2008-2592: Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.
Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_DEFER_SYS. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable research
nvd
CVE-2016-0472P4MEDIUMCVSS 5.5v11.2.0.4v12.1.0.1+1 more2016-01-21
CVE-2016-0472 [MEDIUM] CVE-2016-0472: Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12
Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality and availability via unknown vectors.
nvd
CVE-2009-1997P4MEDIUMCVSS 5.0v10.2.0.3v11.1.0.72009-10-22
CVE-2009-1997 [MEDIUM] CVE-2009-1997: Unspecified vulnerability in the Authentication component in Oracle Database 10.2.0.3 and 11.1.0.7 a
Unspecified vulnerability in the Authentication component in Oracle Database 10.2.0.3 and 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2023-22071P4MEDIUMCVSS 5.9≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22071 [MEDIUM] CVE-2023-22071: Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affect
Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute on sys.utl_http privilege with network access via Oracle Net to compromise PL/SQL. Successful attacks require human interaction fro
nvd
CVE-2012-1746P4MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1746 [MEDIUM] CVE-2012-1746: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2012-1747.
nvd
CVE-2011-2230P4MEDIUMCVSS 5.0v10.1.0.5v10.2.0.3+4 more2011-07-20
CVE-2011-2230 [MEDIUM] CVE-2011-2230: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2012-1745P4MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1745 [MEDIUM] CVE-2012-1745: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2015-4755P4MEDIUMCVSS 5.0v12.1.0.22015-07-16
CVE-2015-4755 [MEDIUM] CVE-2015-4755: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2019-2484P4MEDIUMCVSS 5.4v5.1v18.22019-07-23
CVE-2019-2484 [MEDIUM] CVE-2019-2484: Vulnerability in the Application Express component of Oracle Database Server. Supported versions tha
Vulnerability in the Application Express component of Oracle Database Server. Supported versions that are affected are 5.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Valid Account privilege with network access via HTTP to compromise Application Express. Successful attacks require human interaction from a person other than
nvd
CVE-2011-0806P4MEDIUMCVSS 5.0v10.1.0.5v10.2.0.4+4 more2011-04-20
CVE-2011-0806 [MEDIUM] CVE-2011-0806: Unspecified vulnerability in the Network Foundation component in Oracle Database Server 10.1.0.5, 10
Unspecified vulnerability in the Network Foundation component in Oracle Database Server 10.1.0.5, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2, when running on Windows, allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2013-1554P4MEDIUMCVSS 5.0v10.2.0.4v10.2.0.5+3 more2013-04-17
CVE-2013-1554 [MEDIUM] CVE-2013-1554: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd