Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
341 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
342 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
343 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
344 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
345 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
346 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
347 Oracle Database 9.0c 9.0.4 1 47 18 3
348 Oracle Database 8.0c 8.0.6.3 0 10 2 2
349 Oracle Database 7.0c 7.0.64 0 3 0 1
350 Oracle Database 5.1c 5.1 0 2 1 1
351 Oracle Database 4.0c 4.0.8 0 2 5 2
352 Oracle Database 21.3c 21.3 0 0 6 5
353 Oracle Database 10.1c 10.1.0.5 1 83 75 16
354 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
341 -
10.0
HIGH Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08. NVD-CWE-noinfo
CVE-2008-0345 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2008-01-18
Show GitHub Exploit DB Packet Storm
342 -
10.0
HIGH Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01. NVD-CWE-noinfo
CVE-2008-0346 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2008-01-18
Show GitHub Exploit DB Packet Storm
343 -
10.0
HIGH Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unkno… NVD-CWE-noinfo
CVE-2008-0347 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2008-01-18
Show GitHub Exploit DB Packet Storm
344 -
10.0
HIGH Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vect… NVD-CWE-noinfo
CVE-2008-0348 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2008-01-18
Show GitHub Exploit DB Packet Storm
345 -
10.0
HIGH Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02. NVD-CWE-noinfo
CVE-2008-0349 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2008-01-18
Show GitHub Exploit DB Packet Storm
346 -
8.5
HIGH Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 up to 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) and execute a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5897 cpe:2.3:a:oracle:database_server:9.2.0.6:*
cpe:2.3:a:oracle:database_server:9.2.0.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2007-11-9
Show GitHub Exploit DB Packet Storm
347 -
6.0
MEDIUM Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-4517 cpe:2.3:a:oracle:database_server:release_2:* 2026-04-23 09:35
2007-11-9
Show GitHub Exploit DB Packet Storm
348 -
6.5
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+ and 10.1.0.5 unknown impact and remote attack vectors, related to (1) Import (DB01) and (2) Advanced Queuing (DB25). NOTE: as of 2007… NVD-CWE-noinfo
CVE-2007-5504 cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
349 -
7.5
HIGH Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to (1) the Export component (DB02),… NVD-CWE-noinfo
CVE-2007-5505 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
350 -
7.8
HIGH The Core RDBMS component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (CPU consumption) via a crafted type 6 Data packe… CWE-399
 Resource Management Errors
CVE-2007-5506 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm