Oracle Database Server vulnerabilities

502 known vulnerabilities affecting oracle/database_server.

Total CVEs
502
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL112HIGH71MEDIUM250LOW69

Vulnerabilities

Page 15 of 26
CVE-2010-0860HIGHCVSS 7.1v9.2.0.8v9.2.0.8dv+3 more2010-04-13
CVE-2010-0860 [HIGH] CVE-2010-0860: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0. Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to the Create User privilege.
nvd
CVE-2010-0867MEDIUMCVSS 4.0v10.2.0.4v11.1.0.7+1 more2010-04-13
CVE-2010-0867 [MEDIUM] CVE-2010-0867: Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0. Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.1.0 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2010-0851MEDIUMCVSS 4.0v9.2.0.8v9.2.0.8dv+2 more2010-04-13
CVE-2010-0851 [MEDIUM] CVE-2010-0851: Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, a Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2010-0852MEDIUMCVSS 5.5v9.2.0.8v9.2.0.8dv+2 more2010-04-13
CVE-2010-0852 [MEDIUM] CVE-2010-0852: Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, a Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2010-0866MEDIUMCVSS 6.5PoCv11.1.0.7v11.2.0.12010-04-13
CVE-2010-0866 [MEDIUM] CVE-2010-0866: Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows re Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0854LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+3 more2010-04-13
CVE-2010-0854 [LOW] CVE-2010-0854: Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10 Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."
nvd
CVE-2010-0870LOWCVSS 3.6PoCv9.2.0.8v9.2.0.8dv2010-04-13
CVE-2010-0870 [LOW] CVE-2010-0870: Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0. Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.
nvd
CVE-2005-4884MEDIUMCVSS 6.8v10.1.0.42010-01-25
CVE-2005-4884 [MEDIUM] CVE-2005-4884: Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allo Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allows remote authenticated attackers to affect availability via unknown vectors, aka DB02.
nvd
CVE-2009-3415CRITICALCVSS 9.0v9.2.0.8v9.2.0.8dv+2 more2010-01-13
CVE-2009-3415 [CRITICAL] CVE-2009-3415: Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0 Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-0071CRITICALCVSS 10.0PoCv9.2.0.8v9.2.0.8dv+3 more2010-01-13
CVE-2010-0071 [CRITICAL] CVE-2010-0071: Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-3411MEDIUMCVSS 4.9v9.2.0.8v9.2.0.8dv+4 more2010-01-13
CVE-2009-3411 [MEDIUM] CVE-2009-3411: Unspecified vulnerability in the Oracle Data Pump component in Oracle Database 11.1.0.7, 10.2.0.3, 1 Unspecified vulnerability in the Oracle Data Pump component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-3414MEDIUMCVSS 4.9v9.2.0.8v9.2.0.8dv+2 more2010-01-13
CVE-2009-3414 [MEDIUM] CVE-2009-3414: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10. Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3413.
nvd
CVE-2009-3410LOWCVSS 3.6v9.2.0.8v9.2.0.8dv+4 more2010-01-13
CVE-2009-3410 [LOW] CVE-2009-3410: Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10 Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-3413LOWCVSS 3.2v9.2.0.8v9.2.0.8dv+2 more2010-01-13
CVE-2009-3413 [LOW] CVE-2009-3413: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10. Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3414.
nvd
CVE-2009-3412LOWCVSS 1.0v9.2.0.8v9.2.0.8dv+1 more2010-01-13
CVE-2009-3412 [LOW] CVE-2009-3412: Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5; and Oracle Application Server 10.1.2.3; allows local users to affect confidentiality via unknown vectors.
nvd
CVE-2009-1985CRITICALCVSS 10.0v9.2.0.8v9.2.0.8dv+2 more2009-10-22
CVE-2009-1985 [CRITICAL] CVE-2009-1985: Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0. Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1992CRITICALCVSS 10.0v9.2.0.8v10.1.0.5+1 more2009-10-22
CVE-2009-1992 [CRITICAL] CVE-2009-1992: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2 Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1979CRITICALCVSS 10.0PoCv10.1.0.5v10.2.0.42009-10-22
CVE-2009-1979 [CRITICAL] CVE-2009-1979: Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10 Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is re
nvd
CVE-2009-1965MEDIUMCVSS 5.4v9.2.0.8v10.1.0.52009-10-22
CVE-2009-1965 [MEDIUM] CVE-2009-1965: Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1. Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1995MEDIUMCVSS 4.9v10.2.0.4v11.1.0.72009-10-22
CVE-2009-1995 [MEDIUM] CVE-2009-1995: Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7 Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_AQ_INV.
nvd