cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 9 of 26
CVE-2019-2571P4MEDIUMCVSS 6.6v11.2.0.4v12.1.0.2+2 more2019-04-23
CVE-2019-2571 [MEDIUM] CVE-2019-2571: Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise RDBMS DataPump. Successful attacks of this vulnerability can result
nvd
CVE-2021-2332P4MEDIUMCVSS 6.7v12.1.0.2v12.2.0.1+1 more2021-10-20
CVE-2021-2332 [MEDIUM] CVE-2021-2332: Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that ar Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle LogMiner. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-1999-0888P4MEDIUMCVSS 4.6PoCv7.3.3v7.3.41999-08-16
CVE-1999-0888 [MEDIUM] CVE-1999-0888: dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
nvd
CVE-2007-3858P3HIGHCVSS 7.5v10.2.0.32007-07-18
CVE-2007-3858 [HIGH] CVE-2007-3858: Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 allow remote authenticated users to Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 allow remote authenticated users to have an unknown impact via (1) EXFSYS.DBMS_RLMGR_UTL in Rules Manager (DB11) and (2) Program Interface (DB13).
nvd
CVE-2007-5506P3HIGHCVSS 7.8v9.0.1.5v9.2.0.8+3 more2007-10-17
CVE-2007-5506 [HIGH] CWE-399 CVE-2007-5506: The Core RDBMS component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 all The Core RDBMS component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (CPU consumption) via a crafted type 6 Data packet, aka DB20.
nvd
CVE-2008-0342P4CRITICALCVSS 10.0v9.2.0.8v10.1.0.5+1 more2008-01-17
CVE-2008-0342 [CRITICAL] CVE-2008-0342: Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, a Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.
nvd
CVE-2008-0345P4CRITICALCVSS 10.0v9.0.1.5v9.2.0.8+5 more2008-01-17
CVE-2008-0345 [CRITICAL] CVE-2008-0345: Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.
nvd
CVE-2018-1000873P4MEDIUMCVSS 6.5v12.1.0.2v12.2.0.1+2 more2018-12-20
CVE-2018-1000873 [MEDIUM] CWE-20 CVE-2018-1000873: Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerabilit
nvd
CVE-2025-53047P4MEDIUMCVSS 5.8≥ 19.3, ≤ 19.28≥ 21.3, ≤ 21.19+1 more2025-10-21
CVE-2025-53047 [MEDIUM] CWE-200 CVE-2025-53047: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions t Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks m
nvd
CVE-2006-1869P4CRITICALCVSS 10.0v8.1.7.4v9.0.1.52006-04-20
CVE-2006-1869 [CRITICAL] CVE-2006-1869: Unspecified vulnerability in Oracle Database Server 8.1.7.4 and 9.0.1.5 has unknown impact and attac Unspecified vulnerability in Oracle Database Server 8.1.7.4 and 9.0.1.5 has unknown impact and attack vectors in the Dictionary component, aka Vuln# DB04.
nvd
CVE-2011-0870P4MEDIUMCVSS 6.8v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-0870 [MEDIUM] CVE-2011-0870: Unspecified vulnerability in the Schema Management component in Oracle Database Server 10.1.0.5, 10. Unspecified vulnerability in the Schema Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2012-1737P4MEDIUMCVSS 6.8v11.1.0.7v11.2.0.2+1 more2012-07-17
CVE-2012-1737 [MEDIUM] CVE-2012-1737: Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Enterprise Manager Grid Control EM Base Platform 10.2.0.5, EM Base Platform 11.1.0.1, EM Plugin for DB 12.1.0.1, and EM Plugin for DB 12.1.0.2, allows remote attackers to affect confidentiality, integrity, and avail
nvd
CVE-2007-2130P4CRITICALCVSS 9.0v9.2.0.1v10.1.0.2+1 more2007-04-18
CVE-2007-2130 [CRITICAL] CVE-2007-2130: Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2 Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.
nvd
CVE-2006-0258P4CRITICALCVSS 10.0v8.1.7.4v9.0.1.52006-01-18
CVE-2006-0258 [CRITICAL] CVE-2006-0258: Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.
nvd
CVE-2011-2257P4MEDIUMCVSS 6.8v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-2257 [MEDIUM] CVE-2011-2257: Unspecified vulnerability in the Database Target Type Menus component in Oracle Database Server 10.1 Unspecified vulnerability in the Database Target Type Menus component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2011-0848P4MEDIUMCVSS 6.8v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-0848 [MEDIUM] CVE-2011-0848: Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10 Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to User Model.
nvd
CVE-2007-2111P4MEDIUMCVSS 6.5v9.0.1.5v9.2.0.7+1 more2007-04-18
CVE-2007-2111 [MEDIUM] CWE-89 CVE-2007-2111: SQL injection vulnerability in the SYS.DBMS_AQADM_SYS package in Oracle Database 9.0.1.5, 9.2.0.7, a SQL injection vulnerability in the SYS.DBMS_AQADM_SYS package in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 allows remote authenticated users to inject arbitrary SQL commands via unknown vectors, aka DB04. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB04 is actually for multiple vulnerabilities.
nvd
CVE-2011-0882P4MEDIUMCVSS 6.8v10.1.0.5v10.2.0.3+2 more2011-07-20
CVE-2011-0882 [MEDIUM] CVE-2011-0882: Unspecified vulnerability in the Content Management component in Oracle Database Server 10.1.0.5, 10 Unspecified vulnerability in the Content Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7; and Oracle Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scheduler.
nvd
CVE-2005-3437P4CRITICALCVSS 10.0v10.1.0.3v10.1.0.42005-11-02
CVE-2005-3437 [CRITICAL] CVE-2005-3437: Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has un Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# DB01.
nvd
CVE-2006-0256P4CRITICALCVSS 10.0v8.1.7.4v9.0.1.5+2 more2006-01-18
CVE-2006-0256 [CRITICAL] CVE-2006-0256: Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1 Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.
nvd
Oracle Database Server vulnerabilities | cvebase