Lucene search

K
cveMitreCVE-2007-0272
HistoryJan 17, 2007 - 2:28 a.m.

CVE-2007-0272

2007-01-1702:28:00
CWE-119
mitre
web.nvd.nist.gov
42
oracle database
buffer overflow
mdsys.md
denial of service
arbitrary code execution
cve-2007-0272

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.021

Percentile

89.1%

Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.

Affected configurations

Nvd
Node
oracledatabase_serverMatch8.1.7.4
OR
oracledatabase_serverMatch9.0.1.5
OR
oracledatabase_serverMatch9.2.0.7
OR
oracledatabase_serverMatch10.1.0.4
VendorProductVersionCPE
oracledatabase_server8.1.7.4cpe:2.3:a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*
oracledatabase_server9.0.1.5cpe:2.3:a:oracle:database_server:9.0.1.5:*:*:*:*:*:*:*
oracledatabase_server9.2.0.7cpe:2.3:a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*
oracledatabase_server10.1.0.4cpe:2.3:a:oracle:database_server:10.1.0.4:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.021

Percentile

89.1%