Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 7 of 26
CVE-2012-3132P3MEDIUMCVSS 6.5v10.2.0.3v10.2.0.4+4 more2012-08-10
CVE-2012-3132 [MEDIUM] CWE-89 CVE-2012-3132: SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0
SQL injection vulnerability in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to execute arbitrary SQL commands via vectors involving CREATE INDEX with a CTXSYS.CONTEXT INDEXTYPE and DBMS_STATS.GATHER_TABLE_STATS.
nvd
CVE-2006-0270P3CRITICALCVSS 10.0v10.2.0.12006-01-18
CVE-2006-0270 [CRITICAL] CWE-310 CVE-2006-0270: Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Databa
Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key
nvd
CVE-2024-20903P3MEDIUMCVSS 6.5≥ 19.3, ≤ 19.21≥ 21.3, ≤ 21.122024-02-17
CVE-2024-20903 [MEDIUM] CVE-2024-20903: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.21 and 21.3-21.12. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in
nvd
CVE-2007-2113P3HIGHCVSS 7.5v10.1.0.52007-04-18
CVE-2007-2113 [HIGH] CWE-89 CVE-2007-2113: SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Da
SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Database 10.1.0.5 allows remote authenticated users to execute arbitrary SQL commands via unknown vectors, aka DB07. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB07 is actually for multiple issues.
nvd
CVE-2005-0297P3HIGHCVSS 7.5v10.2.12005-01-18
CVE-2005-0297 [HIGH] CVE-2005-0297: SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitra
SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.
nvd
CVE-2019-2516P3HIGHCVSS 8.2v11.2.0.4v12.1.0.2+2 more2019-04-23
CVE-2019-2516 [HIGH] CVE-2019-2516: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions th
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Cluste
nvd
CVE-2002-0857P4HIGHCVSS 7.5v7.3.4v9.0+1 more2002-09-05
CVE-2002-0857 [HIGH] CVE-2002-0857: Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
nvd
CVE-2006-0261P4CRITICALCVSS 10.0v8.1.7.4v9.0.1.5+2 more2006-01-18
CVE-2006-0261 [CRITICAL] CVE-2006-0261: Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component. NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storag
nvd
CVE-2006-0290P4CRITICALCVSS 10.0v9.2.0.72006-01-18
CVE-2006-0290 [CRITICAL] CVE-2006-0290: Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1
Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.
nvd
CVE-2019-2909P3MEDIUMCVSS 6.8v11.2.0.4v12.1.0.2+3 more2019-10-16
CVE-2019-2909 [MEDIUM] CVE-2019-2909: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additi
nvd
CVE-2006-0551P3HIGHCVSS 7.5v10.1.0.3v10.1.0.4+2 more2006-02-04
CVE-2006-0551 [HIGH] CVE-2006-0551: SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlie
SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by
nvd
CVE-2005-1197P3HIGHCVSS 7.5v10.1.0.2v10.1.0.3+2 more2005-05-02
CVE-2005-1197 [HIGH] CVE-2005-1197: SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle D
SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.
nvd
CVE-2006-1875P3CRITICALCVSS 10.0v9.0.1.5v9.2.0.7+1 more2006-04-20
CVE-2006-1875 [CRITICAL] CVE-2006-1875: Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impac
Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11. NOTE: Oracle has not disputed reliable researcher claims that this issue is SQL injection in MDSYS.SDO_LRS_TRIG_INS.
nvd
CVE-2008-0346P3CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0346 [CRITICAL] CVE-2008-0346: Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 a
Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.
nvd
CVE-2007-5530P3CRITICALCVSS 10.0v10.1.0.5v10.2.0.32007-10-17
CVE-2007-5530 [CRITICAL] CVE-2007-5530: Unspecified vulnerability in the Database Control component in Oracle Database 10.1.0.5 and 10.2.0.3
Unspecified vulnerability in the Database Control component in Oracle Database 10.1.0.5 and 10.2.0.3, and Enterprise Manager, has unknown impact and remote attack vectors, aka EM01.
nvd
CVE-2007-0275P4LOWCVSS 3.5PoCv9.2.0.8v10.1.0.5+1 more2007-01-17
CVE-2007-0275 [LOW] CWE-79 CVE-2007-0275: Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow C
Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to i
nvd
CVE-2006-1876P3CRITICALCVSS 9.0v9.2.0.7v10.1.0.42006-04-20
CVE-2006-1876 [CRITICAL] CVE-2006-1876: Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and atta
Unspecified vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.4 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB12. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the (1) GE
nvd
CVE-2006-5336P3CRITICALCVSS 9.0v9.2.0.7v10.1.0.5+1 more2006-10-18
CVE-2006-5336 [CRITICAL] CVE-2006-5336: Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9
Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06). NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that
nvd
CVE-2006-0283P4CRITICALCVSS 10.0v10.1.0.4.22006-01-18
CVE-2006-0283 [CRITICAL] CVE-2006-0283: Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and C
Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects & Convert Tablespace component.
nvd
CVE-2011-0822P3MEDIUMCVSS 6.8v10.1.0.5v10.2.0.32011-07-20
CVE-2011-0822 [MEDIUM] CVE-2011-0822: Unspecified vulnerability in the Streams, AQ & Replication Mgmt component in Oracle Database Server
Unspecified vulnerability in the Streams, AQ & Replication Mgmt component in Oracle Database Server 10.1.0.5 and 10.2.0.3, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd