Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 23 of 26
CVE-2014-4289P4LOWCVSS 3.6v11.1.0.7v11.2.0.3+2 more2014-10-15
CVE-2014-4289 [LOW] CVE-2014-4289: Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0
Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-6544.
nvd
CVE-2014-6544P4LOWCVSS 3.6v11.1.0.7v11.2.0.3+2 more2014-10-15
CVE-2014-6544 [LOW] CVE-2014-6544: Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0
Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-4289.
nvd
CVE-2013-5764P4LOWCVSS 3.5v11.1.0.7v11.2.0.3+1 more2014-01-15
CVE-2013-5764 [LOW] CVE-2013-5764: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2001-0942P4MEDIUMCVSS 4.6v8.1.6v8.1.72001-11-29
CVE-2001-0942 [MEDIUM] CVE-2001-0942: dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the d
dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.
nvd
CVE-2008-2608P4MEDIUMCVSS 4.0v10.1.0.5v10.2.0.32008-07-15
CVE-2008-2608 [MEDIUM] CVE-2008-2608: Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5 and 10.2.0.3 has un
Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote authenticated attack vectors related to SYS.KUPF$FILE_INT.
nvd
CVE-2007-0278P4MEDIUMCVSS 6.8v8.1.7.4v9.0.1.5+2 more2007-01-17
CVE-2007-0278 [MEDIUM] CVE-2007-0278: Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have
Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14).
nvd
CVE-2005-3205P4LOWCVSS 3.5v9.0.2.42005-10-14
CVE-2005-3205 [LOW] CWE-79 CVE-2005-3205: Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
nvd
CVE-2009-3410P4LOWCVSS 3.6v9.2.0.8v9.2.0.8dv+4 more2010-01-13
CVE-2009-3410 [LOW] CVE-2009-3410: Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10
Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2011-3511P4LOWCVSS 3.6v10.2.0.3v10.2.0.4+3 more2011-10-18
CVE-2011-3511 [LOW] CVE-2011-3511: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2 allows remote authenticated users to affect integrity and availability via unknown vectors related to Privileged Account.
nvd
CVE-2011-2322P4LOWCVSS 3.6v11.1.0.72011-10-18
CVE-2011-2322 [LOW] CVE-2011-2322: Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.1.0.7 allows
Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.1.0.7 allows remote authenticated users to affect integrity and availability, related to SYSDBA.
nvd
CVE-2011-0793P4LOWCVSS 3.6v10.2.0.3v10.2.0.4+3 more2011-04-20
CVE-2011-0793 [LOW] CVE-2011-0793: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect integrity and availability, related to SYSDBA.
nvd
CVE-2011-2243P4LOWCVSS 3.5v11.1.0.7.3v11.2.0.1+1 more2011-07-20
CVE-2011-2243 [LOW] CVE-2011-2243: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7.3, 11.2.0.1
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7.3, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect integrity, related to SYSDBA.
nvd
CVE-2001-0831P4MEDIUMCVSS 4.6v8.1.7v9.0.12001-12-06
CVE-2001-0831 [MEDIUM] CVE-2001-0831: Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality,
Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.
nvd
CVE-2011-0804P4LOWCVSS 3.6v10.2.0.3v10.2.0.4+4 more2011-04-20
CVE-2011-0804 [LOW] CVE-2011-0804: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2021-2175P4LOWCVSS 2.7v12.1.0.2v12.2.0.1+2 more2021-04-22
CVE-2021-2175 [LOW] CVE-2021-2175: Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are
Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any View, Select Any View privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerabil
nvd
CVE-2014-2478P4LOWCVSS 2.6v11.1.0.7v11.2.0.3+2 more2014-10-15
CVE-2014-2478 [LOW] CVE-2014-2478: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2016-3562P4LOWCVSS 2.4v11.2.0.4v12.1.0.22016-10-25
CVE-2016-3562 [LOW] CWE-200 CVE-2016-3562: Unspecified vulnerability in the RDBMS Security and SQL*Plus components in Oracle Database Server 11
Unspecified vulnerability in the RDBMS Security and SQL*Plus components in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality via vectors related to DBA.
nvd
CVE-2009-1972P4LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+3 more2009-10-22
CVE-2009-1972 [LOW] CVE-2009-1972: Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL and DBMS_SQL.
nvd
CVE-2007-0277P4MEDIUMCVSS 6.8v10.1.0.42007-01-17
CVE-2007-0277 [MEDIUM] CVE-2007-0277: Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vect
Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.
nvd
CVE-2020-2731P4LOWCVSS 3.9v12.1.0.2v12.2.0.1+2 more2020-01-15
CVE-2020-2731 [LOW] CVE-2020-2731: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human interactio
nvd