cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 24 of 26
CVE-2019-2955P4LOWCVSS 3.9v11.2.0.4v12.1.0.2+3 more2019-10-16
CVE-2019-2955 [LOW] CVE-2019-2955: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human
nvd
CVE-2019-2954P4LOWCVSS 3.9v11.2.0.4v12.1.0.2+3 more2019-10-16
CVE-2019-2954 [LOW] CVE-2019-2954: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful a
nvd
CVE-2019-2547P4LOWCVSS 3.5v11.2.0.4v12.1.0.2+2 more2019-01-16
CVE-2019-2547 [LOW] CVE-2019-2547: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks require human intera
nvd
CVE-2009-3413P4LOWCVSS 3.2v9.2.0.8v9.2.0.8dv+2 more2010-01-13
CVE-2009-3413 [LOW] CVE-2009-3413: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10. Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3414.
nvd
CVE-2021-35576P4LOWCVSS 2.7v12.1.0.2v12.2.0.1+1 more2021-10-20
CVE-2021-35576 [LOW] CVE-2021-35576: Vulnerability in the Oracle Database Enterprise Edition Unified Audit component of Oracle Database S Vulnerability in the Oracle Database Enterprise Edition Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Oracle Net to compromise Oracle Database Enterprise Edition Unified
nvd
CVE-2008-2590P4LOWCVSS 3.5v10.1.0.52008-07-15
CVE-2008-2590 [LOW] CVE-2008-2590: Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enter Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enterprise Manager 10.1.0.6 has unknown impact and remote authenticated attack vectors.
nvd
CVE-2010-4420P4LOWCVSS 3.6v10.2.0.3v10.2.0.4+3 more2011-01-19
CVE-2010-4420 [LOW] CVE-2010-4420: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0 Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows local users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2016-5498P4LOWCVSS 3.3v11.2.0.4v12.1.0.22016-10-25
CVE-2016-5498 [LOW] CWE-200 CVE-2016-5498: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4 and 12. Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5499.
nvd
CVE-2016-5499P4LOWCVSS 3.3v11.2.0.4v12.1.0.22016-10-25
CVE-2016-5499 [LOW] CVE-2016-5499: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4 and 12. Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5498.
nvd
CVE-2023-22052P4LOWCVSS 3.1≥ 19.3, ≤ 19.19≥ 21.3, ≤ 21.102023-07-18
CVE-2023-22052 [LOW] CVE-2023-22052: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can re
nvd
CVE-2024-21251P4LOWCVSS 3.1≥ 19.3, ≤ 19.24≥ 21.3, ≤ 21.15+1 more2024-10-15
CVE-2024-21251 [LOW] CWE-203 CVE-2024-21251: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerabi
nvd
CVE-2024-21174P4LOWCVSS 3.1≥ 19.3, ≤ 19.23≥ 21.3, ≤ 21.14+1 more2024-07-16
CVE-2024-21174 [LOW] CWE-770 CVE-2024-21174: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability
nvd
CVE-2010-0900P4LOWCVSS 2.6v9.2.0.8v10.1.0.5+3 more2010-07-13
CVE-2010-0900 [LOW] CVE-2010-0900: Unspecified vulnerability in the Network Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5 Unspecified vulnerability in the Network Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2025-53051P4LOWCVSS 2.7≥ 23.4, ≤ 23.92025-10-21
CVE-2025-53051 [LOW] CWE-125 CVE-2025-53051: Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2010-0854P4LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+3 more2010-04-13
CVE-2010-0854 [LOW] CVE-2010-0854: Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10 Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."
nvd
CVE-2015-2585P4LOWCVSS 2.1≤ 4.2.52015-07-16
CVE-2015-2585 [LOW] CVE-2015-2585: Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0 Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0 allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2013-3790P4LOWCVSS 2.1v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3790 [LOW] CVE-2013-3790: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Privileged Account.
nvd
CVE-2017-3240P4LOWCVSS 3.3v12.1.0.22017-01-27
CVE-2017-3240 [LOW] CWE-200 CVE-2017-3240: Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where RDBMS Security executes to compromise RDBMS Security. Successful attacks of this vulnerability can r
nvd
CVE-2025-61749P4LOWCVSS 2.7≥ 23.4, ≤ 23.92025-10-21
CVE-2025-61749 [LOW] CWE-284 CVE-2025-61749: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorized update, inser
nvd
CVE-2021-2000P4LOWCVSS 2.4v12.1.0.2v12.2.0.1+2 more2021-01-20
CVE-2021-2000 [LOW] CVE-2021-2000: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having SYS Account privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks require human interaction from a person ot
nvd
Oracle Database Server vulnerabilities | cvebase