Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 17 of 26
CVE-2005-4884P4MEDIUMCVSS 6.8v10.1.0.42010-01-25
CVE-2005-4884 [MEDIUM] CVE-2005-4884: Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allo
Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allows remote authenticated attackers to affect availability via unknown vectors, aka DB02.
nvd
CVE-2007-5515P4MEDIUMCVSS 6.5v9.2.0.8v9.2.0.8dv+3 more2007-10-17
CVE-2007-5515 [MEDIUM] CVE-2007-5515: Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.2, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB27.
nvd
CVE-2007-5509P4MEDIUMCVSS 6.5v9.2.0.8v9.2.0.8dv2007-10-17
CVE-2007-5509 [MEDIUM] CVE-2007-5509: Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unkn
Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06.
nvd
CVE-2014-6483P4MEDIUMCVSS 6.0≤ 4.2.52014-10-15
CVE-2014-6483 [MEDIUM] CVE-2014-6483: Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.
Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-7067P4MEDIUMCVSS 6.0v10.2.12007-03-02
CVE-2006-7067 [MEDIUM] CVE-2006-7067: Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and po
Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was originally disputed by a third party, but the dispute was retracted. NOTE: this issue was called an "integer overflow" in the original source, but
nvd
CVE-2010-0852P4MEDIUMCVSS 5.5v9.2.0.8v9.2.0.8dv+2 more2010-04-13
CVE-2010-0852 [MEDIUM] CVE-2010-0852: Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, a
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-0987P4MEDIUMCVSS 5.5v9.2.0.8v9.2.0.8dv+2 more2009-07-14
CVE-2009-0987 [MEDIUM] CVE-2009-0987: Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2010-2412P4MEDIUMCVSS 5.5v11.1.0.72010-10-14
CVE-2010-2412 [MEDIUM] CVE-2010-2412: Unspecified vulnerability in the OLAP component in Oracle Database Server 11.1.0.7 allows remote aut
Unspecified vulnerability in the OLAP component in Oracle Database Server 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2011-0787P4MEDIUMCVSS 5.5v11.1.0.72011-04-20
CVE-2011-0787 [MEDIUM] CVE-2011-0787: Unspecified vulnerability in the Application Service Level Management component in Oracle Database S
Unspecified vulnerability in the Application Service Level Management component in Oracle Database Server 11.1.0.7 and Enterprise Manager Grid Control allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Service Level Agreements.
nvd
CVE-2012-0512P4MEDIUMCVSS 5.5v11.1.0.7v11.2.0.22012-05-03
CVE-2012-0512 [MEDIUM] CVE-2012-0512: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 11.1.0.7 and 11.2.0.2 and Oracle Enterprise Manager Grid Control allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Enterprise Config Management.
nvd
CVE-2009-1995P4MEDIUMCVSS 4.9v10.2.0.4v11.1.0.72009-10-22
CVE-2009-1995 [MEDIUM] CVE-2009-1995: Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_AQ_INV.
nvd
CVE-2023-22034P4MEDIUMCVSS 4.9≥ 19.3, ≤ 19.19≥ 21.3, ≤ 21.102023-07-18
CVE-2023-22034 [MEDIUM] CVE-2023-22034: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2012-0520P4MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+3 more2012-05-03
CVE-2012-0520 [MEDIUM] CVE-2012-0520: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2, and in Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote attackers to affect integrity via unknown vectors related to Security Framework.
nvd
CVE-2008-2600P4MEDIUMCVSS 6.5v10.1.0.5v10.2.0.32008-07-15
CVE-2008-2600 [MEDIUM] CVE-2008-2600: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to MDSYS.SDO_TOPO_MAP.
nvd
CVE-2008-2591P4MEDIUMCVSS 6.5v10.2.0.3v11.1.0.62008-07-15
CVE-2008-2591 [MEDIUM] CVE-2008-2591: Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.
Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.
nvd
CVE-2009-1967P4MEDIUMCVSS 5.5v11.1.0.72009-07-14
CVE-2009-1967 [MEDIUM] CVE-2009-1967: Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2)
Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1966.
nvd
CVE-2009-1966P4MEDIUMCVSS 5.5v11.1.0.72009-07-14
CVE-2009-1966 [MEDIUM] CVE-2009-1966: Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2)
Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1967.
nvd
CVE-2013-3826P4MEDIUMCVSS 5.0v11.1.0.7v11.2.0.2+2 more2013-10-16
CVE-2013-3826 [MEDIUM] CVE-2013-3826: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2013-1519P4MEDIUMCVSS 5.0v4.2.12013-04-17
CVE-2013-1519 [MEDIUM] CVE-2013-1519: Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.
Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2010-3590P4MEDIUMCVSS 4.9v10.2.0.4v11.1.0.7+1 more2011-01-19
CVE-2010-3590 [MEDIUM] CVE-2010-3590: Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.4, 11.1.0
Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality and integrity, related to MDSYS.
nvd