cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 26 of 26
CVE-2001-0942MEDIUMCVSS 4.6v8.1.6v8.1.72001-11-29
CVE-2001-0942 [MEDIUM] CVE-2001-0942: dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the d dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.
nvd
CVE-2001-0943HIGHCVSS 7.2v8.0.5v8.1.52001-08-31
CVE-2001-0943 [HIGH] CVE-2001-0943: dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
nvd
CVE-2001-1041LOWCVSS 2.1v8.0v8.1+1 more2001-08-31
CVE-2001-1041 [LOW] CVE-2001-1041: oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
nvd
CVE-2001-0515MEDIUMCVSS 5.0v7.32001-07-21
CVE-2001-0515 [MEDIUM] CVE-2001-0515: Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malf Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.
nvd
CVE-1999-0784MEDIUMCVSS 5.0v7.1.4v7.3.32001-03-12
CVE-1999-0784 [MEDIUM] CVE-1999-0784: Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, ak Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
nvd
CVE-1999-0888MEDIUMCVSS 4.6PoCv7.3.3v7.3.41999-08-16
CVE-1999-0888 [MEDIUM] CVE-1999-0888: dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
nvd