cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 16 of 26
CVE-2007-3856P4MEDIUMCVSS 6.5v9.2.0.7v9.2.0.8+3 more2007-07-18
CVE-2007-3856 [MEDIUM] CVE-2007-3856: Unspecified vulnerability in the Oracle Data Mining component for Oracle Database 10g Release 2 10.2 Unspecified vulnerability in the Oracle Data Mining component for Oracle Database 10g Release 2 10.2.0.2 and 10.2.0.3, 10g 10.1.0.5, and Oracle9i Database Release 2 9.2.0.7, 9.2.0.8, and 9.2.0.8DV has unknown impact and remote authenticated attack vectors related to DMSYS.DMP_SYS, aka DB04.
nvd
CVE-2007-5514P4MEDIUMCVSS 6.5v10.2.0.32007-10-17
CVE-2007-5514 [MEDIUM] CVE-2007-5514: Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and attack vect Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and attack vectors related to (1) Database Vault component (DB24) and (2) SQL Execution component (DB26).
nvd
CVE-2007-5507P4MEDIUMCVSS 6.4v9.0.1.5v9.2.0.8+3 more2007-10-17
CVE-2007-5507 [MEDIUM] CWE-20 CVE-2007-5507: The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9 The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (crash) or read potentially sensitive memory via a connect GIOP packet with an invalid data size, which triggers a buffer over-read, aka DB22.
nvd
CVE-2007-1442P4HIGHCVSS 7.2v10.2.1v10.2.2+1 more2007-03-14
CVE-2007-1442 [HIGH] CVE-2007-1442: Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.
nvd
CVE-2008-2613P4MEDIUMCVSS 6.5v10.2.0.4v11.1.0.62008-07-15
CVE-2008-2613 [MEDIUM] CVE-2008-2613: Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0 Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path issue that allows local users to gain privile
nvd
CVE-2010-0902P4MEDIUMCVSS 6.0v9.2.0.8v9.2.0.8dv+4 more2010-07-13
CVE-2010-0902 [MEDIUM] CVE-2010-0902: Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2009-1021P4MEDIUMCVSS 5.5v9.2.0.8v9.2.0.8dv+2 more2009-07-14
CVE-2009-1021 [MEDIUM] CVE-2009-1021: Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8D Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-1973P4MEDIUMCVSS 5.5v10.1.0.5v10.2.0.4+1 more2009-07-14
CVE-2009-1973 [MEDIUM] CVE-2009-1973: Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10. Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to VPD policies.
nvd
CVE-2015-2655P4MEDIUMCVSS 5.5≤ 4.2.32015-07-16
CVE-2015-2655 [MEDIUM] CVE-2015-2655: Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2. Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.3.00.08 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2019-2956P4MEDIUMCVSS 5.7v12.1.0.2v12.2.0.1+2 more2019-10-16
CVE-2019-2956 [MEDIUM] CVE-2019-2956: Vulnerability in the Core RDBMS (jackson-databind) component of Oracle Database Server. Supported ve Vulnerability in the Core RDBMS (jackson-databind) component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise Core RDBMS (jackson-databind). Successful atta
nvd
CVE-2011-0816P4MEDIUMCVSS 5.5v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-0816 [MEDIUM] CVE-2011-0816: Unspecified vulnerability in the CMDB Metadata & Instance APIs component in Oracle Database Server 1 Unspecified vulnerability in the CMDB Metadata & Instance APIs component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2011-0831P4MEDIUMCVSS 5.5v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-0831 [MEDIUM] CVE-2011-0831: Unspecified vulnerability in the Enterprise Config Management component in Oracle Database Server 10 Unspecified vulnerability in the Enterprise Config Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2015-4857P4MEDIUMCVSS 5.5v12.1.0.1v12.1.0.22015-10-21
CVE-2015-4857 [MEDIUM] CVE-2015-4857: Unspecified vulnerability in the RDBMS component in Oracle Database Server 12.1.0.1 and 12.1.0.2 all Unspecified vulnerability in the RDBMS component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2013-5853P4MEDIUMCVSS 5.0v11.1.0.7v11.2.0.3+1 more2014-01-15
CVE-2013-5853 [MEDIUM] CVE-2013-5853: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2012-1747P4MEDIUMCVSS 5.0v10.2.0.3v10.2.0.4+4 more2012-07-17
CVE-2012-1747 [MEDIUM] CVE-2012-1747: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0. Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Windows, allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2012-1746.
nvd
CVE-2013-1538P4MEDIUMCVSS 5.0v11.2.0.2v11.2.0.32013-04-17
CVE-2013-1538 [MEDIUM] CVE-2013-1538: Unspecified vulnerability in the Network Layer component in Oracle Database Server 11.2.0.2 and 11.2 Unspecified vulnerability in the Network Layer component in Oracle Database Server 11.2.0.2 and 11.2.0.3 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2019-2913P4MEDIUMCVSS 5.0v12.2.0.1v18c+1 more2019-10-16
CVE-2019-2913 [MEDIUM] CVE-2019-2913: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impa
nvd
CVE-2019-2939P4MEDIUMCVSS 5.0v12.2.0.1v18c+1 more2019-10-16
CVE-2019-2939 [MEDIUM] CVE-2019-2939: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impa
nvd
CVE-2018-2875P4MEDIUMCVSS 5.0v12.2.0.1v18c+1 more2019-10-16
CVE-2018-2875 [MEDIUM] CVE-2018-2875: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impa
nvd
CVE-2024-21058P4MEDIUMCVSS 4.9≥ 19.3, ≤ 19.22≥ 21.3, ≤ 21.132024-04-16
CVE-2024-21058 [MEDIUM] CVE-2024-21058: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorized
nvd
Oracle Database Server vulnerabilities | cvebase