cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 6 of 26
CVE-2006-5332P3CRITICALCVSS 9.0v9.2.0.6v10.1.0.42006-10-18
CVE-2006-5332 [CRITICAL] CVE-2006-5332: Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10 Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB01 is for PL/SQL injection in the ENABLE_HIERARCHY_INTERNAL procedure.
nvd
CVE-2018-2939P3HIGHCVSS 8.4v11.2.0.4v12.1.0.2+3 more2018-07-18
CVE-2018-2939 [HIGH] CVE-2018-2939: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. While the vulnerability is in
nvd
CVE-2006-5341P3CRITICALCVSS 9.0v9.2.0.7v10.1.0.5+1 more2006-10-18
CVE-2006-5341 [CRITICAL] CVE-2006-5341: Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10 Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_xdbz. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB14 is for SQL injection in the PITRIG_DROP a
nvd
CVE-2001-0941P4MEDIUMCVSS 4.6PoCv8.0.6v8.1.6+2 more2001-11-30
CVE-2001-0941 [MEDIUM] CVE-2001-0941: Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.
nvd
CVE-2006-3700P3CRITICALCVSS 10.0v9.2.0.6v10.1.0.42006-07-21
CVE-2006-3700 [CRITICAL] CVE-2006-3700: Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.
nvd
CVE-2006-0257P3CRITICALCVSS 10.0v9.2.0.7v10.1.0.5+1 more2006-01-18
CVE-2006-0257 [CRITICAL] CVE-2006-0257: Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10 Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL
nvd
CVE-2006-0259P3CRITICALCVSS 10.0v10.1.0.52006-01-18
CVE-2006-0259 [CRITICAL] CVE-2006-0259: Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component. NOTE: details are unavailable from Oracle, but they have not publicly
nvd
CVE-2006-1866P3CRITICALCVSS 9.7v8.1.7.4v9.0.1.5+2 more2006-04-20
CVE-2006-1866 [CRITICAL] CVE-2006-1866: Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they
nvd
CVE-2007-2114P3CRITICALCVSS 9.0v10.1.0.5v10.2.0.22007-04-18
CVE-2007-2114 [CRITICAL] CVE-2007-2114: Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact an Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors, related to (1) Change Data Capture (CDC), aka DB08, and (2) Oracle Instant Client, aka DB11. NOTE: as of 20070424, oracle has not disputed reliable claims that these issues are buffer overflows using a long CHANGE_TABLE_
nvd
CVE-2006-0271P3CRITICALCVSS 10.0v8.1.7.42006-01-18
CVE-2006-0271 [CRITICAL] CVE-2006-0271: Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9. Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the proble
nvd
CVE-2007-0272P3HIGHCVSS 8.5v8.1.7.4v9.0.1.5+2 more2007-01-17
CVE-2007-0272 [HIGH] CWE-119 CVE-2007-0272: Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 all Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.
nvd
CVE-2008-0348P3CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0348 [CRITICAL] CVE-2008-0348: Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise an Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.
nvd
CVE-2004-1363P3CRITICALCVSS 9.8v8.1.7.4v9.0.1.4+5 more2004-08-04
CVE-2004-1363 [CRITICAL] CWE-131 CVE-2004-1363: Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via envir Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
nvd
CVE-2003-0222P3CRITICALCVSS 9.0v7.3.3v7.3.4+12 more2003-05-12
CVE-2003-0222 [CRITICAL] CWE-119 CVE-2003-0222: Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earli Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
nvd
CVE-2010-0903P3HIGHCVSS 7.8v9.2.0.8v10.1.0.5+3 more2010-07-13
CVE-2010-0903 [HIGH] CVE-2010-0903: Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 1 Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-0911P3HIGHCVSS 7.8v9.2.0.8v9.2.0.8dv+4 more2010-07-13
CVE-2010-0911 [HIGH] CVE-2010-0911: Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10 Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2007-5897P3HIGHCVSS 8.5v9.2.0.1v9.2.0.2+7 more2007-11-08
CVE-2007-5897 [HIGH] CVE-2007-5897: Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 up to 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via the TRANSFORM function. NOTE: this issue might already be covered by CVE-2007-5515, CVE-2007-5509, or CVE-2007-5505, but there are insufficient det
nvd
CVE-2006-0291P3CRITICALCVSS 10.0v10.2.0.12006-01-18
CVE-2006-0291 [CRITICAL] CVE-2006-0291: Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.
nvd
CVE-2005-3445P3CRITICALCVSS 10.0v8.1.7.4v9.2.0.5+5 more2005-11-02
CVE-2005-3445 [CRITICAL] CVE-2005-3445: Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 an Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05.
nvd
CVE-2020-2969P3MEDIUMCVSS 6.6v11.2.0.4v12.1.0.2+3 more2020-07-15
CVE-2020-2969 [MEDIUM] CVE-2020-2969: Vulnerability in the Data Pump component of Oracle Database Server. Supported versions that are affe Vulnerability in the Data Pump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows high privileged attacker having DBA role account privilege with network access via Oracle Net to compromise Data Pump. Successful attacks of this vulnerability can res
nvd
Oracle Database Server vulnerabilities | cvebase