Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
351 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
352 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
353 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
354 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
355 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
356 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
357 Oracle Database 9.0c 9.0.4 1 47 18 3
358 Oracle Database 8.0c 8.0.6.3 0 10 2 2
359 Oracle Database 7.0c 7.0.64 0 3 0 1
360 Oracle Database 5.1c 5.1 0 2 1 1
361 Oracle Database 4.0c 4.0.8 0 2 5 2
362 Oracle Database 21.3c 21.3 0 0 6 5
363 Oracle Database 10.1c 10.1.0.5 1 83 75 16
364 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
351 -
6.4
MEDIUM The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (cra… CWE-20
CWE-119
 Improper Input Validation 
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-5507 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
352 -
6.5
MEDIUM Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execut… CWE-89
SQL Injection
CVE-2007-5508 cpe:2.3:a:oracle:database_server:10.2.0.3:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
353 -
6.5
MEDIUM Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06. NVD-CWE-noinfo
CVE-2007-5509 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
354 -
7.5
HIGH Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV and 10.2.0.3 has unknown impact and remote attack vectors, aka DB21. NVD-CWE-noinfo
CVE-2007-5512 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:10.2.0.3:*
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
355 -
5.0
MEDIUM The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect audit entries in the USERID column in which (1) long usernames are trimmed to 5 characters, or (2)… NVD-CWE-Other
CVE-2007-5513 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
356 -
6.5
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and attack vectors related to (1) Database Vault component (DB24) and (2) SQL Execution component (DB26). NVD-CWE-noinfo
CVE-2007-5514 cpe:2.3:a:oracle:database_server:10.2.0.3:* 2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
357 -
6.5
MEDIUM Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.2, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB27. NVD-CWE-noinfo
CVE-2007-5515 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
358 -
7.5
HIGH Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8 and 9.2.0.8DV, and Oracle Application Server 9.0.4.3, 10.1.3.0.0 up to 10.1.3.3.0, and 10.1.2.0.1 up to… NVD-CWE-noinfo
CVE-2007-5520 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
359 -
10.0
HIGH Unspecified vulnerability in the Database Control component in Oracle Database 10.1.0.5 and 10.2.0.3, and Enterprise Manager, has unknown impact and remote attack vectors, aka EM01. NVD-CWE-noinfo
CVE-2007-5530 cpe:2.3:a:oracle:database_server:10.2.0.3:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm
360 -
10.0
HIGH Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM… NVD-CWE-noinfo
CVE-2007-5531 cpe:2.3:a:oracle:database_server:10.2.0.3:* 2026-04-23 09:35
2007-10-18
Show GitHub Exploit DB Packet Storm