Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 4 of 26
CVE-2016-9842P3HIGHCVSS 8.8v18c2017-05-23
CVE-2016-9842 [HIGH] CWE-1335 CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
nvd
CVE-2016-9840P3HIGHCVSS 8.8v18c2017-05-23
CVE-2016-9840 [HIGH] CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by lever
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2012-0552P3CRITICALCVSS 9.0v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0552 [CRITICAL] CVE-2012-0552: Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.3, 10.2.0
Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2014-6545P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2014-10-15
CVE-2014-6545 [CRITICAL] CVE-2014-6545: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6467, and CVE-2014-6560.
nvd
CVE-2014-6467P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2014-10-15
CVE-2014-6467 [CRITICAL] CVE-2014-6467: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6545, and CVE-2014-6560.
nvd
CVE-2014-6453P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2014-10-15
CVE-2014-6453 [CRITICAL] CVE-2014-6453: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6467, CVE-2014-6545, and CVE-2014-6560.
nvd
CVE-2014-6560P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2014-10-15
CVE-2014-6560 [CRITICAL] CVE-2014-6560: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6467, and CVE-2014-6545.
nvd
CVE-2024-21184P3HIGHCVSS 7.2≥ 19.3, ≤ 19.232024-07-16
CVE-2024-21184 [HIGH] CWE-250 CVE-2024-21184: Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported
Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security. Successful attacks of this
nvd
CVE-2014-6546P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2014-10-15
CVE-2014-6546 [CRITICAL] CVE-2014-6546: Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2014-6455P3CRITICALCVSS 9.0v11.1.0.7v11.2.0.3+3 more2014-10-15
CVE-2014-6455 [CRITICAL] CVE-2014-6455: Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2023-21893P3HIGHCVSS 7.5v19cv21c2023-01-18
CVE-2023-21893 [HIGH] CWE-284 CVE-2023-21893: Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported v
Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than t
nvd
CVE-2006-1868P3HIGHCVSS 7.5v10.1.0.42006-04-20
CVE-2006-1868 [HIGH] CWE-119 CVE-2006-1868: Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows data
Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03.
nvd
CVE-2012-3220P3CRITICALCVSS 9.0v10.2.0.3v10.2.0.4+4 more2013-01-17
CVE-2012-3220 [CRITICAL] CVE-2012-3220: Unspecified vulnerability in the Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.
Unspecified vulnerability in the Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users with Create Session privileges to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-9843P3CRITICALCVSS 9.8v18c2017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unsp
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
nvd
CVE-2002-0843P3HIGHCVSS 7.5v8.1.7v9.2.22002-10-11
CVE-2002-0843 [HIGH] CVE-2002-0843: Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Ap
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
nvd
CVE-2006-2505P4LOWCVSS 3.6PoCvrelease_22006-05-22
CVE-2006-2505 [LOW] CVE-2006-2505: Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a refer
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious package in the TYPE_NAME argument in the (1) GET_DOMAIN_INDEX_TABLES or (2) GET_V2_DOMAIN_INDEX_TABLES function in the DBMS_EXPORT_EXTENSION package.
nvd
CVE-2020-2511P3HIGHCVSS 7.7v12.1.0.2v12.2.0.1+2 more2020-01-15
CVE-2020-2511 [HIGH] CVE-2020-2511: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significan
nvd
CVE-2011-2301P3HIGHCVSS 8.5v10.1.0.5v10.2.0.3+2 more2011-10-18
CVE-2011-2301 [HIGH] CVE-2011-2301: Unspecified vulnerability in the Oracle Text component in Oracle Database Server 10.1.0.5, 10.2.0.3,
Unspecified vulnerability in the Oracle Text component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to CTXSYS.DRVDISP.
nvd
CVE-2014-2406P3HIGHCVSS 8.5v11.1.0.7v11.2.0.3+2 more2014-04-16
CVE-2014-2406 [HIGH] CVE-2014-2406: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to "Advisor" and "Select Any Dictionary" privileges.
nvd
CVE-2006-3702P3CRITICALCVSS 10.0v8.1.7.4v9.2.0.7+2 more2006-07-21
CVE-2006-3702 [CRITICAL] CVE-2006-3702: Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.
Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB06 in Export; (2) DB08, (3) DB09, (4) DB10, (5) DB11, (6) DB12, (7) DB13, (8) DB14, and (9) DBC01 for OCI; (10) DB16 for Query Rewrite/Summary Mgmt; (11) DB17, (12) DB18, (13) DB19, (14) DBC
nvd