Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 17 of 26
CVE-2009-1967MEDIUMCVSS 5.5v11.1.0.72009-07-14
CVE-2009-1967 [MEDIUM] CVE-2009-1967: Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2)
Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1966.
nvd
CVE-2009-1015MEDIUMCVSS 4.0v9.2.0.8v9.2.0.8dv+2 more2009-07-14
CVE-2009-1015 [MEDIUM] CVE-2009-1015: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2009-1021MEDIUMCVSS 5.5v9.2.0.8v9.2.0.8dv+2 more2009-07-14
CVE-2009-1021 [MEDIUM] CVE-2009-1021: Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8D
Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2009-1970MEDIUMCVSS 5.0PoCv9.2.0.8v9.2.0.8dv+3 more2009-07-14
CVE-2009-1970 [MEDIUM] CVE-2009-1970: Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991.
nvd
CVE-2009-1966MEDIUMCVSS 5.5v11.1.0.72009-07-14
CVE-2009-1966 [MEDIUM] CVE-2009-1966: Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2)
Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1967.
nvd
CVE-2009-1973MEDIUMCVSS 5.5v10.1.0.5v10.2.0.4+1 more2009-07-14
CVE-2009-1973 [MEDIUM] CVE-2009-1973: Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.
Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to VPD policies.
nvd
CVE-2009-1969LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+3 more2009-07-14
CVE-2009-1969 [LOW] CVE-2009-1969: Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2009-0997MEDIUMCVSS 4.0v11.1.0.62009-04-15
CVE-2009-0997 [MEDIUM] CVE-2009-0997: Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote
Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL.
nvd
CVE-2009-0972MEDIUMCVSS 6.5v9.2.0.8v9.2.0.8dv+5 more2009-04-15
CVE-2009-0972 [MEDIUM] CVE-2009-0972: Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7,
Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-6065MEDIUMCVSS 5.1PoCv10.1v10.2+1 more2009-02-05
CVE-2008-6065 [MEDIUM] CVE-2008-6065: Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathname
Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file thro
nvd
CVE-2008-2611MEDIUMCVSS 4.0v10.1.0.52008-07-15
CVE-2008-2611 [MEDIUM] CVE-2008-2611: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.
nvd
CVE-2008-2613MEDIUMCVSS 6.5v10.2.0.4v11.1.0.62008-07-15
CVE-2008-2613 [MEDIUM] CVE-2008-2613: Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0
Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path issue that allows local users to gain privile
nvd
CVE-2008-2600MEDIUMCVSS 6.5v10.1.0.5v10.2.0.32008-07-15
CVE-2008-2600 [MEDIUM] CVE-2008-2600: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to MDSYS.SDO_TOPO_MAP.
nvd
CVE-2008-2605MEDIUMCVSS 4.0v11.1.0.62008-07-15
CVE-2008-2605 [MEDIUM] CVE-2008-2605: Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown im
Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2604.
nvd
CVE-2008-2592MEDIUMCVSS 5.5v9.2.0.8v10.1.0.52008-07-15
CVE-2008-2592 [MEDIUM] CVE-2008-2592: Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.
Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_DEFER_SYS. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable research
nvd
CVE-2008-2602MEDIUMCVSS 4.6v10.1.0.5v10.2.0.4+1 more2008-07-15
CVE-2008-2602 [MEDIUM] CVE-2008-2602: Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1
Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to the IMP_FULL_DATABASE role.
nvd
CVE-2008-2607MEDIUMCVSS 6.5v10.1.0.5v10.2.0.4+1 more2008-07-15
CVE-2008-2607 [MEDIUM] CVE-2008-2607: Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 1
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_AQELM. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this iss
nvd
CVE-2008-2608MEDIUMCVSS 4.0v10.1.0.5v10.2.0.32008-07-15
CVE-2008-2608 [MEDIUM] CVE-2008-2608: Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5 and 10.2.0.3 has un
Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote authenticated attack vectors related to SYS.KUPF$FILE_INT.
nvd
CVE-2008-2604MEDIUMCVSS 6.5v11.1.0.62008-07-15
CVE-2008-2604 [MEDIUM] CVE-2008-2604: Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown im
Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2605.
nvd
CVE-2008-2591MEDIUMCVSS 6.5v10.2.0.3v11.1.0.62008-07-15
CVE-2008-2591 [MEDIUM] CVE-2008-2591: Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.
Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.
nvd