Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 22 of 26
CVE-2014-4245P4LOWCVSS 3.5v11.1.0.7v11.2.0.3+2 more2014-07-17
CVE-2014-4245 [LOW] CVE-2014-4245: Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-1999-0784P4MEDIUMCVSS 5.0v7.1.4v7.3.32001-03-12
CVE-1999-0784 [MEDIUM] CVE-1999-0784: Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, ak
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
nvd
CVE-2002-0856P4MEDIUMCVSS 5.0v9.2.12002-09-05
CVE-2002-0856 [MEDIUM] CVE-2002-0856: SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
nvd
CVE-2007-2110P4MEDIUMCVSS 4.4v9.0.1.5v9.2.0.7+1 more2007-04-18
CVE-2007-2110 [MEDIUM] CVE-2007-2110: Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5+, 9.2.0.7, and 10.
Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB03 occurs because RDBMS uses a NULL Discretionary Access Control List (DACL) for the Oracle process and certain shared
nvd
CVE-2010-0867P4MEDIUMCVSS 4.0v10.2.0.4v11.1.0.7+1 more2010-04-13
CVE-2010-0867 [MEDIUM] CVE-2010-0867: Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.
Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.1.0 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2009-1015P4MEDIUMCVSS 4.0v9.2.0.8v9.2.0.8dv+2 more2009-07-14
CVE-2009-1015 [MEDIUM] CVE-2009-1015: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2024-21066P4MEDIUMCVSS 4.2≥ 19.3, ≤ 19.22≥ 21.3, ≤ 21.132024-04-16
CVE-2024-21066 [MEDIUM] CWE-79 CVE-2024-21066: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affecte
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS executes to compromise RDBMS. Successful attacks require human interaction
nvd
CVE-2007-0273P4MEDIUMCVSS 4.3v9.0.1.5v9.2.0.8+2 more2007-01-17
CVE-2007-0273 [MEDIUM] CVE-2007-0273: Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown im
Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.
nvd
CVE-2008-2605P4MEDIUMCVSS 4.0v11.1.0.62008-07-15
CVE-2008-2605 [MEDIUM] CVE-2008-2605: Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown im
Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2604.
nvd
CVE-2012-0534P4MEDIUMCVSS 4.0v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0534 [MEDIUM] CVE-2012-0534: Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 10.2.0.3, 10.2.0.4,
Unspecified vulnerability in the RDBMS Core component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Create Session.
nvd
CVE-2015-0370P4LOWCVSS 3.5v11.1.0.7v11.2.0.3+2 more2015-01-21
CVE-2015-0370 [LOW] CVE-2015-0370: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2013-5858.
nvd
CVE-2023-21949P4LOWCVSS 3.7≥ 19.3, ≤ 19.19≥ 21.3, ≤ 21.102023-07-18
CVE-2023-21949 [LOW] CVE-2023-21949: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported vers
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2001-0515P4MEDIUMCVSS 5.0v7.32001-07-21
CVE-2001-0515 [MEDIUM] CVE-2001-0515: Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malf
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.
nvd
CVE-2011-0811P4MEDIUMCVSS 4.9v10.1.0.5v10.2.0.3+1 more2011-07-20
CVE-2011-0811 [MEDIUM] CVE-2011-0811: Unspecified vulnerability in the Enterprise Config Management component in Oracle Database Server 10
Unspecified vulnerability in the Enterprise Config Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4, and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5, allows local users to affect confidentiality via unknown vectors.
nvd
CVE-2008-2611P4MEDIUMCVSS 4.0v10.1.0.52008-07-15
CVE-2008-2611 [MEDIUM] CVE-2008-2611: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.
nvd
CVE-2007-0276P4MEDIUMCVSS 6.8v8.1.7.4v9.0.1.52007-01-17
CVE-2007-0276 [MEDIUM] CVE-2007-0276: Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and
Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16).
nvd
CVE-2014-0378P4MEDIUMCVSS 4.1v11.1.0.7v11.2.0.3+2 more2014-01-15
CVE-2014-0378 [MEDIUM] CVE-2014-0378: Unspecified vulnerability in the Spatial component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Spatial component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2019-2569P4MEDIUMCVSS 4.0v11.2.0.4v12.1.0.2+1 more2019-07-23
CVE-2019-2569 [MEDIUM] CVE-2019-2569: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human inte
nvd
CVE-2009-1971P4LOWCVSS 3.5v10.1.0.5v10.2.0.3+1 more2009-10-22
CVE-2009-1971 [LOW] CVE-2009-1971: Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1
Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2010-2391P4LOWCVSS 3.6v10.1.0.5v10.2.0.32010-10-14
CVE-2010-2391 [LOW] CVE-2010-2391: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5 and 10.2.0.
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd