Lucene search

K

Database Security Vulnerabilities

cve
cve

CVE-2003-0449

Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter,...

7.1AI Score

0.0004EPSS

2003-08-07 04:00 AM
17
cve
cve

CVE-2007-6674

Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.

5.7AI Score

0.002EPSS

2008-01-08 07:46 PM
19
cve
cve

CVE-2008-1814

Unspecified vulnerability in the Oracle Secure Enterprise Search or Ultrasearch component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3 and 10.1.2.2; and Oracle Collaboration Suite 10.1.2; has unknown impact and remote attack vectors, aka D...

8.9AI Score

0.002EPSS

2008-04-16 10:05 AM
77
4
cve
cve

CVE-2008-2592

Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_DEFER_SYS. NOTE: the previous information was obtained from the Oracl...

6.1AI Score

0.002EPSS

2008-07-15 11:41 PM
72
cve
cve

CVE-2008-2600

Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to MDSYS.SDO_TOPO_MAP.

5.4AI Score

0.004EPSS

2008-07-15 11:41 PM
67
cve
cve

CVE-2008-2611

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.

5.8AI Score

0.007EPSS

2008-07-15 11:41 PM
55
cve
cve

CVE-2010-0076

Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

5.7AI Score

0.004EPSS

2010-01-13 01:30 AM
20
cve
cve

CVE-2014-3566

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

3.4CVSS

4.4AI Score

0.975EPSS

2014-10-15 12:55 AM
651
5
cve
cve

CVE-2016-0677

Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.

5.9CVSS

5.5AI Score

0.002EPSS

2016-04-21 10:59 AM
38
cve
cve

CVE-2016-0690

Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0691.

3.3CVSS

3.6AI Score

0.0004EPSS

2016-04-21 10:59 AM
22
cve
cve

CVE-2016-0691

Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690.

3.3CVSS

3.6AI Score

0.0004EPSS

2016-04-21 10:59 AM
23
cve
cve

CVE-2016-2183

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted sess...

7.5CVSS

6.5AI Score

0.005EPSS

2016-09-01 12:59 AM
1013
In Wild
7
cve
cve

CVE-2016-3454

Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

9CVSS

8.4AI Score

0.002EPSS

2016-04-21 11:00 AM
28
cve
cve

CVE-2016-3479

Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.

7.5CVSS

7.8AI Score

0.005EPSS

2016-07-21 10:12 AM
23
4
cve
cve

CVE-2016-3484

Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality and integrity via unknown vectors.

3.4CVSS

5.2AI Score

0.0004EPSS

2016-07-21 10:12 AM
29
cve
cve

CVE-2016-3488

Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows local users to affect integrity via unknown vectors.

4.4CVSS

5.8AI Score

0.0004EPSS

2016-07-21 10:12 AM
27
cve
cve

CVE-2016-3489

Unspecified vulnerability in the Data Pump Import component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

6.7CVSS

6.9AI Score

0.0004EPSS

2016-07-21 10:12 AM
36
4
cve
cve

CVE-2016-3609

Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

9CVSS

8AI Score

0.002EPSS

2016-07-21 10:14 AM
38
4
cve
cve

CVE-2016-5497

Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

6.4CVSS

5.9AI Score

0.0004EPSS

2016-10-25 02:29 PM
23
cve
cve

CVE-2016-5572

Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

6.4CVSS

5.9AI Score

0.0004EPSS

2016-10-25 02:30 PM
20
cve
cve

CVE-2017-10120

Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.0.2. Difficult to exploit vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with logon to the infrastructure where RDBMS Securit...

1.9CVSS

2.8AI Score

0.001EPSS

2017-08-08 03:29 PM
39
cve
cve

CVE-2017-10190

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Java ...

8.2CVSS

8.2AI Score

0.0004EPSS

2017-10-19 05:29 PM
36
2
cve
cve

CVE-2017-10202

Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to co...

9.9CVSS

8.1AI Score

0.002EPSS

2017-08-08 03:29 PM
44
3
cve
cve

CVE-2017-10261

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where XML Database executes to comp...

6.5CVSS

6.6AI Score

0.001EPSS

2017-10-19 05:29 PM
32
cve
cve

CVE-2017-10282

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromis...

9.1CVSS

8.3AI Score

0.001EPSS

2018-01-18 02:29 AM
40
2
cve
cve

CVE-2017-10292

Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with logon to the infrastructure where RDBMS Security exec...

2.3CVSS

3.6AI Score

0.001EPSS

2017-10-19 05:29 PM
31
2
cve
cve

CVE-2017-10321

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create session privilege with logon to the infrastructure where Core RDBMS executes t...

8.8CVSS

8.5AI Score

0.0004EPSS

2017-10-19 05:29 PM
33
2
cve
cve

CVE-2017-3240

Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where RDBMS Security executes to compromise RDBM...

3.3CVSS

3.7AI Score

0.001EPSS

2017-01-27 10:59 PM
35
4
cve
cve

CVE-2017-3310

Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise O...

9CVSS

8.2AI Score

0.002EPSS

2017-01-27 10:59 PM
33
4
cve
cve

CVE-2017-3567

Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise...

5.3CVSS

4.9AI Score

0.001EPSS

2017-04-24 07:59 PM
27
cve
cve

CVE-2018-1288

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

5.4CVSS

5.5AI Score

0.001EPSS

2018-07-26 02:29 PM
57
cve
cve

CVE-2018-2575

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with network access via multiple protocols to compromise Co...

2CVSS

2.8AI Score

0.001EPSS

2018-01-18 02:29 AM
32
cve
cve

CVE-2018-2680

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks require...

8.3CVSS

8.1AI Score

0.002EPSS

2018-01-18 02:29 AM
49
cve
cve

CVE-2018-2841

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols ...

8.5CVSS

8.2AI Score

0.001EPSS

2018-04-19 02:29 AM
41
cve
cve

CVE-2018-2875

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the ...

5CVSS

4.2AI Score

0.001EPSS

2019-10-16 06:15 PM
26
cve
cve

CVE-2018-2939

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS e...

8.4CVSS

8.2AI Score

0.001EPSS

2018-07-18 01:29 PM
39
cve
cve

CVE-2018-3004

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2,12.2.0.1 and 18.2. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple proto...

5.3CVSS

4.9AI Score

0.002EPSS

2018-07-18 01:29 PM
34
cve
cve

CVE-2018-3110

A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to comp...

9.9CVSS

8.7AI Score

0.002EPSS

2018-08-10 10:29 PM
64
cve
cve

CVE-2018-3259

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of t...

9.8CVSS

8.9AI Score

0.011EPSS

2018-10-17 01:31 AM
86
cve
cve

CVE-2019-2406

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to comp...

7.2CVSS

7.2AI Score

0.002EPSS

2019-01-16 07:30 PM
22
2
cve
cve

CVE-2019-2444

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core ...

8.2CVSS

8.2AI Score

0.0004EPSS

2019-01-16 07:30 PM
27
2
cve
cve

CVE-2019-2516

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure w...

8.2CVSS

8.2AI Score

0.0004EPSS

2019-04-23 07:32 PM
26
cve
cve

CVE-2019-2517

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having DBFS_ROLE privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerab...

9.1CVSS

8.2AI Score

0.003EPSS

2019-04-23 07:32 PM
48
cve
cve

CVE-2019-2518

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple ...

7.5CVSS

7.6AI Score

0.001EPSS

2019-04-23 07:32 PM
41
cve
cve

CVE-2019-2547

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protoco...

3.5CVSS

3.3AI Score

0.001EPSS

2019-01-16 07:30 PM
37
cve
cve

CVE-2019-2569

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes t...

4CVSS

4.2AI Score

0.0004EPSS

2019-07-23 11:15 PM
83
cve
cve

CVE-2019-2571

Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise RDBMS...

6.6CVSS

6.7AI Score

0.001EPSS

2019-04-23 07:32 PM
44
cve
cve

CVE-2019-2582

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can ...

5.3CVSS

4.9AI Score

0.001EPSS

2019-04-23 07:32 PM
39
cve
cve

CVE-2019-2619

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure w...

8.2CVSS

8.1AI Score

0.0004EPSS

2019-04-23 07:32 PM
34
2
cve
cve

CVE-2019-2734

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Execute on DBMS_ADVISOR privilege with network access via OracleNet to compromi...

4.3CVSS

3.7AI Score

0.001EPSS

2019-10-16 06:15 PM
39
Total number of security vulnerabilities116