Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 19 of 26
CVE-2010-4413P4MEDIUMCVSS 4.3v11.1.0.7v11.2.0.12011-01-19
CVE-2010-4413 [MEDIUM] CVE-2010-4413: Unspecified vulnerability in the Scheduler Agent component in Oracle Database Server 11.1.0.7 and 11
Unspecified vulnerability in the Scheduler Agent component in Oracle Database Server 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2008-1819P4HIGHCVSS 7.2v10.1.0.5v10.2.0.32008-04-16
CVE-2008-1819 [HIGH] CVE-2008-1819: Unspecified vulnerability in the Oracle Net Services component in Oracle Database 9.2.0.8, 10.1.0.5,
Unspecified vulnerability in the Oracle Net Services component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and local attack vectors, aka DB09.
nvd
CVE-2019-2753P4MEDIUMCVSS 4.6v11.2.0.4v12.1.0.2+2 more2019-07-23
CVE-2019-2753 [MEDIUM] CVE-2019-2753: Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are af
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Oracle Text. Successful attacks require human interaction from a per
nvd
CVE-2011-0830P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.3+1 more2011-07-20
CVE-2011-0830 [MEDIUM] CVE-2011-0830: Unspecified vulnerability in the Event Management component in Oracle Database Server 10.1.0.5, 10.2
Unspecified vulnerability in the Event Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors related to Rules Management UI.
nvd
CVE-2011-0877P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.3+1 more2011-07-20
CVE-2011-0877 [MEDIUM] CVE-2011-0877: Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 1
Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2011-0805P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.4+2 more2011-04-20
CVE-2011-0805 [MEDIUM] CVE-2011-0805: Unspecified vulnerability in the UIX component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.
Unspecified vulnerability in the UIX component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2011-0785P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.3+5 more2011-04-20
CVE-2011-0785 [MEDIUM] CVE-2011-0785: Unspecified vulnerability in the Oracle Help component in Oracle Database Server 11.1.0.7, 11.2.0.1,
Unspecified vulnerability in the Oracle Help component in Oracle Database Server 11.1.0.7, 11.2.0.1, 11.2.0.2, 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, and 10.1.0.5; and Oracle Fusion Middleware 11.1.1.2.0, 11.1.1.3.0, and 11.1.1.4.0 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2019-2734P4MEDIUMCVSS 4.3v12.2.0.1v18c+1 more2019-10-16
CVE-2019-2734 [MEDIUM] CVE-2019-2734: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Execute on DBMS_ADVISOR privilege with network access via OracleNet to compromise Core RDBMS. Successful attacks of this vulnerability can re
nvd
CVE-2024-21233P4MEDIUMCVSS 4.3≥ 19.3, ≤ 19.24≥ 21.3, ≤ 21.15+2 more2024-10-15
CVE-2024-21233 [MEDIUM] CWE-203 CVE-2024-21233: Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions t
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Core. Successful attacks of this
nvd
CVE-2023-22096P4MEDIUMCVSS 4.3≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22096 [MEDIUM] CVE-2023-22096: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in
nvd
CVE-2019-12973P4MEDIUMCVSS 5.5v18c2019-06-26
CVE-2019-12973 [MEDIUM] CVE-2019-12973: In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c.
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
nvd
CVE-2016-5505P4MEDIUMCVSS 5.5v11.2.0.4v12.1.0.22016-10-25
CVE-2016-5505 [MEDIUM] CWE-200 CVE-2016-5505: Unspecified vulnerability in the RDBMS Programmable Interface component in Oracle Database Server 11
Unspecified vulnerability in the RDBMS Programmable Interface component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect confidentiality via unknown vectors.
nvd
CVE-2006-1877P4HIGHCVSS 7.2v8.1.7.4v9.0.1.5+1 more2006-04-20
CVE-2006-1877 [HIGH] CVE-2006-1877: Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.7 has unknown impact
Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.7 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB13.
nvd
CVE-2014-4237P4MEDIUMCVSS 4.0v11.2.0.4v12.1.0.12014-07-17
CVE-2014-4237 [MEDIUM] CVE-2014-4237: Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.2.0.4 and 12.1.0.
Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.2.0.4 and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2011-0881P4MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+1 more2011-07-20
CVE-2011-0881 [MEDIUM] CVE-2011-0881: Unspecified vulnerability in the EMCTL component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 1
Unspecified vulnerability in the EMCTL component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2022-21393P4MEDIUMCVSS 4.3v12.1.0.2v12.2.0.1+2 more2022-01-19
CVE-2022-21393 [MEDIUM] CVE-2022-21393: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2023-22073P4MEDIUMCVSS 4.3≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22073 [MEDIUM] CVE-2023-22073: Vulnerability in the Oracle Notification Server component of Oracle Database Server. Supported vers
Vulnerability in the Oracle Notification Server component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Notification Server executes to compromise Oracle
nvd
CVE-2007-0269P4MEDIUMCVSS 5.5v9.2.0.8v10.1.0.5+1 more2007-01-17
CVE-2007-0269 [MEDIUM] CVE-2007-0269: Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and
Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.
nvd
CVE-2016-0461P4MEDIUMCVSS 4.0v11.2.0.4v12.1.0.1+1 more2016-01-21
CVE-2016-0461 [MEDIUM] CVE-2016-0461: Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12
Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2015-2599P4MEDIUMCVSS 4.0v11.1.0.7v11.2.0.3+3 more2015-07-16
CVE-2015-2599 [MEDIUM] CVE-2015-2599: Unspecified vulnerability in the RDBMS Scheduler component in Oracle Database Server 11.1.0.7, 11.2.
Unspecified vulnerability in the RDBMS Scheduler component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd