Oracle Database Server vulnerabilities
502 known vulnerabilities affecting oracle/database_server.
Total CVEs
502
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL112HIGH71MEDIUM250LOW69
Vulnerabilities
Page 21 of 26
CVE-2007-0268MEDIUMCVSS 6.5v9.0.1.5v9.2.0.7+1 more2007-01-17
CVE-2007-0268 [MEDIUM] CVE-2007-0268: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15). NOTE: Oracle has not publicly claims by r
nvd
CVE-2007-0270MEDIUMCVSS 6.5v9.2.0.7v10.1.0.42007-01-17
CVE-2007-0270 [MEDIUM] CWE-119 CVE-2007-0270: Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated
Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.
nvd
CVE-2007-0275LOWCVSS 3.5PoCv9.2.0.8v10.1.0.5+1 more2007-01-17
CVE-2007-0275 [LOW] CWE-79 CVE-2007-0275: Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow C
Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to i
nvd
CVE-2006-5332CRITICALCVSS 9.0v9.2.0.6v10.1.0.42006-10-18
CVE-2006-5332 [CRITICAL] CVE-2006-5332: Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10
Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB01 is for PL/SQL injection in the ENABLE_HIERARCHY_INTERNAL procedure.
nvd
CVE-2006-5338CRITICALCVSS 9.0v10.1.0.5v10.2.0.02006-10-18
CVE-2006-5338 [CRITICAL] CVE-2006-5338: Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact
Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact and remote authenticated attack vectors related to sys.dbms_sqltune, aka Vuln# DB10. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB10 is for SQL injection in DROP_SQLSET, DELETE_SQLSET, SELECT_SQLSET, and I_SET_TUNI
nvd
CVE-2006-5344CRITICALCVSS 9.0v8.1.7.4v9.0.1.5+2 more2006-10-18
CVE-2006-5344 [CRITICAL] CVE-2006-5344: Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vuln# DB20, and (2) mdsys.sdo_cs, aka DB21. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB20 is a
nvd
CVE-2006-5335CRITICALCVSS 9.0v10.1.0.5v10.2.0.22006-10-18
CVE-2006-5335 [CRITICAL] CVE-2006-5335: Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact an
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) Vuln# DB04 and sys.dbms_cdc_impdp in the (a) Change Data Capture (CDC) component; (2) Vuln# DB07, (3) DB08, and (4) DB16 in sys.dbms_cdc_isubscribe in CDC; and (5) mdsys.sdo_geor_int in the (b) Oracle Spati
nvd
CVE-2006-5343CRITICALCVSS 9.0v10.1.0.32006-10-18
CVE-2006-5343 [CRITICAL] CVE-2006-5343: Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown im
Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.
nvd
CVE-2006-5345CRITICALCVSS 9.0v9.0.1.5v9.2.0.7+1 more2006-10-18
CVE-2006-5345 [CRITICAL] CVE-2006-5345: Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.
Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_geom, aka Vuln# DB22. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB22 is related to "length checking" in the RELATE function before
nvd
CVE-2006-5339CRITICALCVSS 9.0v8.1.7.4v9.0.1.5+2 more2006-10-18
CVE-2006-5339 [CRITICAL] CVE-2006-5339: Unspecified vulnerability in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7,
Unspecified vulnerability in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_geom, aka Vuln# DB11. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB11 is related to "length checking" in the RELATE functio
nvd
CVE-2006-5336CRITICALCVSS 9.0v9.2.0.7v10.1.0.5+1 more2006-10-18
CVE-2006-5336 [CRITICAL] CVE-2006-5336: Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9
Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06). NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that
nvd
CVE-2006-5341CRITICALCVSS 9.0v9.2.0.7v10.1.0.5+1 more2006-10-18
CVE-2006-5341 [CRITICAL] CVE-2006-5341: Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10
Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_xdbz. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB14 is for SQL injection in the PITRIG_DROP a
nvd
CVE-2006-5337CRITICALCVSS 9.0v9.0.1.5v9.2.0.8+2 more2006-10-18
CVE-2006-5337 [CRITICAL] CVE-2006-5337: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5,
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 has unknown impact and remote authenticated attack vectors, aka Vuln# DB09.
nvd
CVE-2006-5340HIGHCVSS 7.1v8.1.7.4v9.0.1.5+3 more2006-10-18
CVE-2006-5340 [HIGH] CVE-2006-5340: Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related
nvd
CVE-2006-5334HIGHCVSS 7.1v9.0.1.5v9.2.0.7+1 more2006-10-18
CVE-2006-5334 [HIGH] CVE-2006-5334: Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.
Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and remote authenticated attack vectors related to mdsys.md2, aka Vuln# DB03. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB03 is related to one or more of (1) a buffer overflow in the (a) RELATE f
nvd
CVE-2006-5342HIGHCVSS 7.1v9.0.1.5v9.2.0.6+1 more2006-10-18
CVE-2006-5342 [HIGH] CVE-2006-5342: Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.
Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.3 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_tune, aka Vuln# DB18. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB18 might be related to SQL injection in the EXTENT_OF function.
nvd
CVE-2006-5333HIGHCVSS 7.1v10.2.0.22006-10-18
CVE-2006-5333 [HIGH] CVE-2006-5333: Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact
Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact and remote authenticated attack vectors related to "create session" privileges, aka Vuln# DB02. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB02 is for SQL injection in the SDO_DROP_USER_BEFORE package using a Trigger f
nvd
CVE-2006-3701CRITICALCVSS 9.0v8.1.7.4v9.0.1.5+1 more2006-07-21
CVE-2006-3701 [CRITICAL] CVE-2006-3701: Unspecified vulnerability in the Dictionary component in Oracle Database 8.1.7.4, 9.0.1.5, and 9.2.0
Unspecified vulnerability in the Dictionary component in Oracle Database 8.1.7.4, 9.0.1.5, and 9.2.0.6 has unknown impact and attack vectors, aka Oracle Vuln# DB05.
nvd
CVE-2006-3702CRITICALCVSS 10.0v8.1.7.4v9.2.0.7+2 more2006-07-21
CVE-2006-3702 [CRITICAL] CVE-2006-3702: Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.
Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB06 in Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, and (9) DBC01 for OCI; (10) DB16 for Query Rewrite/Summary Mgmt; (11) DB17, (12) DB18, (13) DB19, (14) DBC
nvd
CVE-2006-3700CRITICALCVSS 10.0v9.2.0.6v10.1.0.42006-07-21
CVE-2006-3700 [CRITICAL] CVE-2006-3700: Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.
nvd