Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
361 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
362 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
363 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
364 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
365 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
366 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
367 Oracle Database 9.0c 9.0.4 1 47 18 3
368 Oracle Database 8.0c 8.0.6.3 0 10 2 2
369 Oracle Database 7.0c 7.0.64 0 3 0 1
370 Oracle Database 5.1c 5.1 0 2 1 1
371 Oracle Database 4.0c 4.0.8 0 2 5 2
372 Oracle Database 21.3c 21.3 0 0 6 5
373 Oracle Database 10.1c 10.1.0.5 1 83 75 16
374 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
361 -
6.5
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to have unknown impact via (1) DBMS_JAVA_TEST in the JavaVM component (DB01), (2) Oracle… NVD-CWE-Other
CVE-2007-3853 cpe:2.3:a:oracle:database_server:10.2.0.3:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
362 -
5.5
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing compo… NVD-CWE-noinfo
CVE-2007-3854 cpe:2.3:a:oracle:database_server:9.2.0.8dv:r2
cpe:2.3:a:oracle:database_server:9.2.0.8:r2
cpe:2.3:a:oracle:databa…
2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
363 -
6.5
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the Da… NVD-CWE-Other
CVE-2007-3855 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
364 -
6.5
MEDIUM Unspecified vulnerability in the Oracle Data Mining component for Oracle Database 10g Release 2 10.2.0.2 and 10.2.0.3, 10g 10.1.0.5, and Oracle9i Database Release 2 9.2.0.7, 9.2.0.8, and 9.2.0.8DV ha… NVD-CWE-Other
CVE-2007-3856 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
365 -
6.5
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 allow remote authenticated users to have an unknown impact via (a) the Oracle Text component, including (1) unspecified vectors (DB05)… NVD-CWE-Other
CVE-2007-3857 cpe:2.3:a:oracle:database_server:10.1.0.5:* 2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
366 -
7.5
HIGH Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 allow remote authenticated users to have an unknown impact via (1) EXFSYS.DBMS_RLMGR_UTL in Rules Manager (DB11) and (2) Program Inter… NVD-CWE-noinfo
CVE-2007-3858 cpe:2.3:a:oracle:database_server:10.2.0.3:* 2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
367 -
7.5
HIGH Unspecified vulnerability in the Oracle Internet Directory component for Oracle Database 9.2.0.8 and 9.2.0.8DV; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 10.1.2 ha… NVD-CWE-Other
CVE-2007-3859 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
2026-04-23 09:35
2007-07-19
Show GitHub Exploit DB Packet Storm
368 -
6.8
MEDIUM Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of … CWE-264
NVD-CWE-noinfo
Permissions, Privileges, and Access Controls
CVE-2007-2108 cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
369 -
4.4
MEDIUM Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03. NOTE: as of 20070424, Or… NVD-CWE-noinfo
CVE-2007-2110 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
370 -
6.5
MEDIUM SQL injection vulnerability in the SYS.DBMS_AQADM_SYS package in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 allows remote authenticated users to inject arbitrary SQL commands via unknown vectors,… CWE-89
SQL Injection
CVE-2007-2111 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm