Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 5 of 26
CVE-2006-0547P3HIGHCVSS 7.5v8.1.7.4v9.2.0.6+5 more2006-02-04
CVE-2006-0547 [HIGH] CVE-2006-0547: Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to th
nvd
CVE-2013-3774P3HIGHCVSS 7.6v10.2.0.4v10.2.0.5+3 more2013-07-17
CVE-2013-3774 [HIGH] CVE-2013-3774: Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.
Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2002-0567P3HIGHCVSS 7.5v8.0.1v8.0.2+9 more2002-07-03
CVE-2002-0567 [HIGH] CVE-2002-0567: Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to by
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
nvd
CVE-2020-2735P3HIGHCVSS 8.0v11.2.0.4v12.1.0.2+3 more2020-04-15
CVE-2020-2735 [HIGH] CVE-2020-2735: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a perso
nvd
CVE-2020-2968P3HIGHCVSS 8.0v11.2.0.4v12.1.0.2+3 more2020-07-15
CVE-2020-2968 [HIGH] CVE-2020-2968: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks require huma
nvd
CVE-2009-3415P3CRITICALCVSS 9.0v9.2.0.8v9.2.0.8dv+2 more2010-01-13
CVE-2009-3415 [CRITICAL] CVE-2009-3415: Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0
Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-0265P3CRITICALCVSS 10.0v8.1.7.4v9.0.1.5+3 more2006-01-18
CVE-2006-0265 [CRITICAL] CVE-2006-0265: Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5,
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component. NOTE: details are unavailable from Oracle, but they have not publicly disputed
nvd
CVE-2008-1817P3CRITICALCVSS 9.0v9.0.1.5v10.1.0.5+2 more2008-04-16
CVE-2008-1817 [CRITICAL] CVE-2008-1817: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 have unknown impact and remote attack vectors related to (1) SDO_IDX in the Spatial component, aka DB07; and (2) Core RDBMS, aka DB10. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliabl
nvd
CVE-2005-3641P3HIGHCVSS 7.5v7.0.2v7.0.64+16 more2005-11-16
CVE-2005-3641 [HIGH] CVE-2005-3641: Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to
Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
nvd
CVE-2007-5531P3CRITICALCVSS 10.0v10.2.0.32007-10-17
CVE-2007-5531 [CRITICAL] CVE-2007-5531: Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Datab
Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02.
nvd
CVE-2006-3705P3CRITICALCVSS 10.0v10.1.0.52006-07-21
CVE-2006-3705 [CRITICAL] CVE-2006-3705: Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vect
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL
nvd
CVE-2008-1818P3CRITICALCVSS 10.0v11.1.0.62008-04-16
CVE-2008-1818 [CRITICAL] CVE-2008-1818: Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown im
Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.
nvd
CVE-2010-0853P3HIGHCVSS 7.5v9.2.0.8v9.2.0.8dv2010-04-13
CVE-2010-0853 [HIGH] CVE-2010-0853: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2.0.8, and DV; and Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2010-2390P3HIGHCVSS 7.5v10.1.0.5v10.2.0.32010-10-14
CVE-2010-2390 [HIGH] CVE-2010-2390: Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server
Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-5344P3CRITICALCVSS 9.0v8.1.7.4v9.0.1.5+2 more2006-10-18
CVE-2006-5344 [CRITICAL] CVE-2006-5344: Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vuln# DB20, and (2) mdsys.sdo_cs, aka DB21. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB20 is a
nvd
CVE-2006-0263P3CRITICALCVSS 10.0v8.1.7.4v9.0.1.5+3 more2006-01-18
CVE-2006-0263 [CRITICAL] CVE-2006-0263: Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component.
nvd
CVE-2003-0096P3CRITICALCVSS 9.0v8.0.6v9.2.1+1 more2003-03-03
CVE-2003-0096 [CRITICAL] CWE-119 CVE-2003-0096: Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow rem
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.
nvd
CVE-2019-2776P3HIGHCVSS 7.6v12.1.0.2v12.2.0.1+2 more2019-07-23
CVE-2019-2776 [HIGH] CVE-2019-2776: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Index privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may signifi
nvd
CVE-2006-0260P3CRITICALCVSS 10.0v9.2.0.7v10.1.0.52006-01-18
CVE-2006-0260 [CRITICAL] CVE-2006-0260: Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified
Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26
nvd
CVE-2008-0347P3CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0347 [CRITICAL] CVE-2008-0347: Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2;
Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.
nvd