cbcvebase.

Oracle Oracle9I vulnerabilities

47 known vulnerabilities affecting oracle/oracle9i.

Total CVEs
47
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH18MEDIUM19LOW2

Vulnerabilities

Page 1 of 3
CVE-2002-0965P3HIGHCVSS 7.5PoCv9.0v9.0.1+1 more2002-10-04
CVE-2002-0965 [HIGH] CVE-2002-0965: Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.
nvd
CVE-2004-1364P3HIGHCVSS 8.5PoCvclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1364 [HIGH] CWE-22 CVE-2004-1364: Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
nvd
CVE-2002-0840P4MEDIUMCVSS 6.8PoCv9.0v9.0.1+3 more2002-10-11
CVE-2002-0840 [MEDIUM] CVE-2002-0840: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
nvd
CVE-2004-0637P3MEDIUMCVSS 6.5PoCventerprise_9.2.0.4vpersonal_9.2.0.4+2 more2004-09-02
CVE-2004-0637 [MEDIUM] CWE-94 CVE-2004-0637: Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additiona Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.
nvd
CVE-2004-1707P4HIGHCVSS 7.2PoCvclient_9.2.0.1vclient_9.2.0.2+30 more2004-07-30
CVE-2004-1707 [HIGH] CVE-2004-1707: The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix syste The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
nvd
CVE-2005-3204P4MEDIUMCVSS 4.3PoCvclient_9.2.0.1vclient_9.2.0.2+42 more2005-10-14
CVE-2005-3204 [MEDIUM] CVE-2005-3204: Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arb Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
nvd
CVE-2003-0095P3CRITICALCVSS 10.0v9.0v9.0.1+3 more2003-03-03
CVE-2003-0095 [CRITICAL] CWE-119 CVE-2003-0095: Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote atta Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.
nvd
CVE-2002-0563P3MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0563 [MEDIUM] CWE-287 CVE-2002-0563: The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to a The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (
nvd
CVE-2004-1371P3CRITICALCVSS 9.0vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1371 [CRITICAL] CWE-119 CVE-2004-1371: Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code v Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
nvd
CVE-2002-0561P3HIGHCVSS 7.5v9.0v9.0.12002-07-03
CVE-2002-0561 [HIGH] CVE-2002-0561: The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Applicatio The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.
nvd
CVE-2002-0567P3HIGHCVSS 7.5v9.0v9.0.12002-07-03
CVE-2002-0567 [HIGH] CVE-2002-0567: Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to by Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
nvd
CVE-2005-3641P3HIGHCVSS 7.5venterprise_8.1.7venterprise_9.0.1+42 more2005-11-16
CVE-2005-3641 [HIGH] CVE-2005-3641: Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
nvd
CVE-2003-0096P3CRITICALCVSS 9.0v9.0v9.0.1+3 more2003-03-03
CVE-2003-0096 [CRITICAL] CWE-119 CVE-2003-0096: Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow rem Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.
nvd
CVE-2004-1362P3HIGHCVSS 7.5vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1362 [HIGH] CVE-2004-1362: The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
nvd
CVE-2002-0564P3HIGHCVSS 7.5v9.0v9.0.12002-07-03
CVE-2002-0564 [HIGH] CVE-2002-0564: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass au PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.
nvd
CVE-2004-1370P3HIGHCVSS 7.5vclient_9.2.0.1vclient_9.2.0.2+34 more2004-08-04
CVE-2004-1370 [HIGH] CVE-2004-1370: Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9 Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
nvd
CVE-2006-0271P3CRITICALCVSS 10.0venterprise_9.0.1.5vstandard_9.2.0.72006-01-18
CVE-2006-0271 [CRITICAL] CVE-2006-0271: Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9. Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the proble
nvd
CVE-2004-0638P3HIGHCVSS 8.5venterprise_9.0.1.4venterprise_9.0.1.5+10 more2004-12-31
CVE-2004-0638 [HIGH] CWE-119 CVE-2004-0638: Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9 Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.
nvd
CVE-2003-0222P3CRITICALCVSS 9.0v9.0v9.0.1+6 more2003-05-12
CVE-2003-0222 [CRITICAL] CWE-119 CVE-2003-0222: Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earli Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
nvd
CVE-2003-1208P4CRITICALCVSS 10.0venterprise_9.0.1venterprise_9.2.0+15 more2004-12-03
CVE-2003-1208 [CRITICAL] CVE-2003-1208: Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.
nvd