cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 8 of 26
CVE-2010-4421P3MEDIUMCVSS 6.8v10.2.0.3v10.2.0.4+3 more2011-01-19
CVE-2010-4421 [MEDIUM] CVE-2010-4421: Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0 Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2006-0285P4CRITICALCVSS 10.0v8.1.7.4v9.0.1.5+1 more2006-01-18
CVE-2006-0285 [CRITICAL] CVE-2006-0285: Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0. Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01.
nvd
CVE-2006-0286P4CRITICALCVSS 10.0v9.0.1.5v9.2.0.7+1 more2006-01-18
CVE-2006-0286 [CRITICAL] CVE-2006-0286: Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0 Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.
nvd
CVE-2005-3438P4CRITICALCVSS 10.0≤ 10.1.0.4.22005-11-02
CVE-2005-3438 [CRITICAL] CVE-2005-3438: Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impa Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle Label Security; (7) DB27 in Security, possib
nvd
CVE-2019-2749P3MEDIUMCVSS 6.8v11.2.0.4v12.1.0.2+3 more2019-07-23
CVE-2019-2749 [MEDIUM] CVE-2019-2749: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vu
nvd
CVE-2011-2244P3MEDIUMCVSS 6.4v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-2244 [MEDIUM] CVE-2011-2244: Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10 Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality and integrity via unknown vectors related to Authentication.
nvd
CVE-2006-0548P4HIGHCVSS 7.5v10.1.0.4.22006-02-04
CVE-2006-0548 [HIGH] CVE-2006-0548: SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlie SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been add
nvd
CVE-2008-0344P4CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0344 [CRITICAL] CVE-2008-0344: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 h Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.
nvd
CVE-2008-0349P4CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0349 [CRITICAL] CVE-2008-0349: Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edward Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.
nvd
CVE-2008-0340P4CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0340 [CRITICAL] CVE-2008-0340: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).
nvd
CVE-2014-6577P3MEDIUMCVSS 6.8v11.2.0.3v11.2.0.4+2 more2015-01-21
CVE-2014-6577 [MEDIUM] CVE-2014-6577: Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2. Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the original researcher's claim that this is an XML e
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v12.2.0.1v18c+1 more2018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2006-5335P4CRITICALCVSS 9.0v10.1.0.5v10.2.0.22006-10-18
CVE-2006-5335 [CRITICAL] CVE-2006-5335: Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact an Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) Vuln# DB04 and sys.dbms_cdc_impdp in the (a) Change Data Capture (CDC) component; (2) Vuln# DB07, (3) DB08, and (4) DB16 in sys.dbms_cdc_isubscribe in CDC; and (5) mdsys.sdo_geor_int in the (b) Oracle Spati
nvd
CVE-2008-1821P4CRITICALCVSS 9.0v9.0.1.5v10.1.0.52008-04-16
CVE-2008-1821 [CRITICAL] CVE-2008-1821: Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+, and 10 Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+, and 10.1.0.5 has unknown impact and remote attack vectors related to SYS.DBMS_AQJMS_INTERNAL, aka DB15. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that DB15 is for multiple buffer over
nvd
CVE-2006-5338P4CRITICALCVSS 9.0v10.1.0.5v10.2.0.02006-10-18
CVE-2006-5338 [CRITICAL] CVE-2006-5338: Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact and remote authenticated attack vectors related to sys.dbms_sqltune, aka Vuln# DB10. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB10 is for SQL injection in DROP_SQLSET, DELETE_SQLSET, SELECT_SQLSET, and I_SET_TUNI
nvd
CVE-2006-0282P4CRITICALCVSS 10.0v8.1.7.4v9.0.1.5+2 more2006-01-18
CVE-2006-0282 [CRITICAL] CVE-2006-0282: Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10. Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.
nvd
CVE-2011-0852P4MEDIUMCVSS 6.8v10.1.0.5v10.2.0.3+1 more2011-07-20
CVE-2011-0852 [MEDIUM] CVE-2011-0852: Unspecified vulnerability in the Security Management component in Oracle Database Server 10.1.0.5, 1 Unspecified vulnerability in the Security Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, and 10.2.0.4; and Oracle Enterprise Manager Grid Control 10.1.0.6; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Audit Administration.
nvd
CVE-2006-1871P3MEDIUMCVSS 6.5v9.2.0.7v10.1.0.52006-04-20
CVE-2006-1871 [MEDIUM] CWE-89 CVE-2006-1871: SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers t SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06.
nvd
CVE-2011-2248P4MEDIUMCVSS 6.8v11.1.0.7v11.2.0.1+1 more2011-07-20
CVE-2011-2248 [MEDIUM] CVE-2011-2248: Unspecified vulnerability in the SQL Performance Advisories/UIs component in Oracle Database Server Unspecified vulnerability in the SQL Performance Advisories/UIs component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality, integrity, and availability, related to SQL Details UI & Explain Plan.
nvd
CVE-2005-3444P4CRITICALCVSS 10.0v8.1.7.4v9.2.0.5+2 more2005-11-02
CVE-2005-3444 [CRITICAL] CVE-2005-3444: Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i up to 9.2.0.5 have unknown impact and attack vectors, aka Oracle Vuln# DB26.
nvd
Oracle Database Server vulnerabilities | cvebase