Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 2 of 26
CVE-2018-3259P2CRITICALCVSS 9.8v11.2.0.4v12.1.0.2+2 more2018-10-17
CVE-2018-3259 [CRITICAL] CVE-2018-3259: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.
nvd
CVE-2007-5508P3MEDIUMCVSS 6.5PoCv10.1.0.5v10.2.0.32007-10-17
CVE-2007-5508 [MEDIUM] CWE-89 CVE-2007-5508: Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text comp
Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthentic
nvd
CVE-2019-16942P3CRITICALCVSS 9.8v12.2.0.1v18c+1 more2019-10-01
CVE-2019-16942 [CRITICAL] CWE-502 CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible
nvd
CVE-2015-4796P3CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2015-10-21
CVE-2015-4796 [CRITICAL] CVE-2015-4796: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4888.
nvd
CVE-2018-3110P3CRITICALCVSS 9.9v11.2.0.4v12.1.0.2+2 more2018-08-10
CVE-2018-3110 [CRITICAL] CVE-2018-3110: A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported version
A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attac
nvd
CVE-2010-2415P3MEDIUMCVSS 4.9PoCv10.1.0.5v10.2.0.4+2 more2010-10-14
CVE-2010-2415 [MEDIUM] CVE-2010-2415: Unspecified vulnerability in the Change Data Capture component in Oracle Database Server 10.1.0.5, 1
Unspecified vulnerability in the Change Data Capture component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_CDC_PUBLISH.
nvd
CVE-2009-1970P3MEDIUMCVSS 5.0PoCv9.2.0.8v9.2.0.8dv+3 more2009-07-14
CVE-2009-1970 [MEDIUM] CVE-2009-1970: Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991.
nvd
CVE-2008-6065P3MEDIUMCVSS 5.1PoCv10.1v10.2+1 more2009-02-05
CVE-2008-6065 [MEDIUM] CVE-2008-6065: Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathname
Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file thro
nvd
CVE-2007-4517P3MEDIUMCVSS 6.0PoCvrelease_22007-11-08
CVE-2007-4517 [MEDIUM] CWE-119 CVE-2007-4517: Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remo
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument.
nvd
CVE-2025-30751P3HIGHCVSS 8.8≥ 19.3, ≤ 19.27≥ 23.4, ≤ 23.82025-07-15
CVE-2025-30751 [HIGH] CWE-863 CVE-2025-30751: Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that a
Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database. Successful attacks of this vulnerabili
nvd
CVE-2009-1985P3CRITICALCVSS 10.0v9.2.0.8v9.2.0.8dv+2 more2009-10-22
CVE-2009-1985 [CRITICAL] CVE-2009-1985: Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2005-3206P4MEDIUMCVSS 5.0PoCv9.0.2.42005-10-14
CVE-2005-3206 [MEDIUM] CVE-2005-3206: iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command.
nvd
CVE-2018-2841P3HIGHCVSS 8.5v11.2.0.4v12.1.0.2+2 more2018-04-19
CVE-2018-2841 [HIGH] CVE-2018-2841: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. While the vulnerability is in Java VM, at
nvd
CVE-2017-10282P3CRITICALCVSS 9.1v12.1.0.2v12.2.0.12018-01-18
CVE-2017-10282 [CRITICAL] CVE-2017-10282: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, at
nvd
CVE-2019-2517P3CRITICALCVSS 9.1v12.2.0.1v18c2019-04-23
CVE-2019-2517 [CRITICAL] CVE-2019-2517: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having DBFS_ROLE privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact add
nvd
CVE-2015-4863P3CRITICALCVSS 10.0v11.2.0.4v12.1.0.1+1 more2015-10-21
CVE-2015-4863 [CRITICAL] CVE-2015-4863: Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4,
Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2014-6567P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2015-01-21
CVE-2014-6567 [CRITICAL] CVE-2014-6567: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that
nvd
CVE-2009-1992P3CRITICALCVSS 10.0v9.2.0.8v10.1.0.5+1 more2009-10-22
CVE-2009-1992 [CRITICAL] CVE-2009-1992: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2013-1534P3CRITICALCVSS 10.0v11.2.0.2v11.2.0.32013-04-17
CVE-2013-1534 [CRITICAL] CVE-2013-1534: Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 1
Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-2381P3HIGHCVSS 7.5v11.2.0.4v12.1.0.2+3 more2016-04-08
CVE-2016-2381 [HIGH] CWE-20 CVE-2016-2381: Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child pro
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
nvd