Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 3 of 26
CVE-2002-1767P4HIGHCVSS 7.2PoCv8.1.52002-12-31
CVE-2002-1767 [HIGH] CVE-2002-1767: Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execut
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument.
nvd
CVE-2010-0870P4LOWCVSS 3.6PoCv9.2.0.8v9.2.0.8dv2010-04-13
CVE-2010-0870 [LOW] CVE-2010-0870: Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.
Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.
nvd
CVE-2003-0095P3CRITICALCVSS 10.0v8.0.6v9.2.1+1 more2003-03-03
CVE-2003-0095 [CRITICAL] CWE-119 CVE-2003-0095: Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote atta
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.
nvd
CVE-2016-9841P3CRITICALCVSS 9.8v18c2017-05-23
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by levera
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2001-0833P4HIGHCVSS 7.2PoC≤ 9.0.1v8.0+1 more2001-12-06
CVE-2001-0833 [HIGH] CVE-2001-0833: Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary cod
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
nvd
CVE-2016-5555P3CRITICALCVSS 9.1v11.2.0.4v12.1.0.22016-10-25
CVE-2016-5555 [CRITICAL] CVE-2016-5555: Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allo
Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2018-2680P3HIGHCVSS 8.3v11.2.0.4v12.1.0.2+1 more2018-01-18
CVE-2018-2680 [HIGH] CVE-2018-2680: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks require human interaction from a person other than the attacker and whi
nvd
CVE-2020-2510P3HIGHCVSS 7.5v11.2.0.4v12.1.0.2+3 more2020-01-15
CVE-2020-2510 [HIGH] CVE-2020-2510: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via OracleNet to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker.
nvd
CVE-2007-2108P3MEDIUMCVSS 6.8v9.0.1.5v9.2.0.8+2 more2007-04-18
CVE-2007-2108 [MEDIUM] CWE-264 CVE-2007-2108: Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5,
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on th
nvd
CVE-2013-3751P3CRITICALCVSS 9.0v11.2.0.2v11.2.0.32013-07-17
CVE-2013-3751 [CRITICAL] CVE-2013-3751: Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3,
Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2019-2799P3HIGHCVSS 7.5v11.2.0.4v12.1.0.2+2 more2019-07-23
CVE-2019-2799 [HIGH] CVE-2019-2799: Vulnerability in the Oracle ODBC Driver component of Oracle Database Server<span class=font-red><b>
Vulnerability in the Oracle ODBC Driver component of Oracle Database Server ***PRIVILEGE CANNOT BE NONE FOR AUTHENTICATED ATTACKS***. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Oracle
nvd
CVE-2015-2629P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2015-07-16
CVE-2015-2629 [CRITICAL] CVE-2015-2629: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-0457.
nvd
CVE-2016-0499P3CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2016-01-21
CVE-2016-0499 [CRITICAL] CVE-2016-0499: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4794.
nvd
CVE-2026-46834P3HIGHCVSS 7.5≥ 23.4.0, ≤ 23.26.22026-05-28
CVE-2026-46834 [HIGH] CWE-400 CVE-2026-46834: Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are a
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently r
nvd
CVE-2026-46835P3HIGHCVSS 7.5≥ 23.4.0, ≤ 23.26.22026-05-28
CVE-2026-46835 [HIGH] CWE-400 CVE-2026-46835: Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are a
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently r
nvd
CVE-2020-2518P3HIGHCVSS 7.5v11.2.0.4v12.1.0.2+3 more2020-01-15
CVE-2020-2518 [HIGH] CVE-2020-2518: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can resu
nvd
CVE-2019-2518P3HIGHCVSS 7.5v11.2.0.4v12.1.0.2+3 more2019-04-23
CVE-2019-2518 [HIGH] CVE-2019-2518: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vuln
nvd
CVE-2015-4794P3CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2015-10-21
CVE-2015-4794 [CRITICAL] CVE-2015-4794: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2015-0457P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2015-04-16
CVE-2015-0457 [CRITICAL] CVE-2015-0457: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-2629.
nvd
CVE-2004-1371P3CRITICALCVSS 9.0v9i_application_server2004-08-04
CVE-2004-1371 [CRITICAL] CWE-119 CVE-2004-1371: Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code v
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
nvd