Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
371 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
372 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
373 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
374 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
375 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
376 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
377 Oracle Database 9.0c 9.0.4 1 47 18 3
378 Oracle Database 8.0c 8.0.6.3 0 10 2 2
379 Oracle Database 7.0c 7.0.64 0 3 0 1
380 Oracle Database 5.1c 5.1 0 2 1 1
381 Oracle Database 4.0c 4.0.8 0 2 5 2
382 Oracle Database 21.3c 21.3 0 0 6 5
383 Oracle Database 10.1c 10.1.0.5 1 83 75 16
384 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
371 -
6.0
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Manager and Expression Filter components (DB02) and (… NVD-CWE-noinfo
CVE-2007-2109 cpe:2.3:a:oracle:database_server:10.2.0.3:* 2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
372 -
6.0
MEDIUM Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and attack vectors, aka DB05. NOTE: as of 20070424, Oracle has not disputed rel… NVD-CWE-noinfo
CVE-2007-2112 cpe:2.3:a:oracle:database_server:10.2.0.3:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
373 -
7.5
HIGH SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Database 10.1.0.5 allows remote authenticated users to execute arbitrary SQL commands via unknown vec… CWE-89
SQL Injection
CVE-2007-2113 cpe:2.3:a:oracle:database_server:10.1.0.5:* 2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
374 -
9.0
HIGH Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors, related to (1) Change Data Capture (CDC), aka DB08, and (2) … NVD-CWE-noinfo
CVE-2007-2114 cpe:2.3:a:oracle:database_server:10.2.0.2:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
375 -
6.8
MEDIUM Unspecified vulnerability in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors, aka DB09. NOTE: as of 20070424, oracle … NVD-CWE-noinfo
CVE-2007-2115 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:10.2.0.2:*
cpe:2.3:a:oracle:database_…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
376 -
9.0
HIGH Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors, aka DB10. NOTE: as of 20070424, Oracle has n… NVD-CWE-noinfo
CVE-2007-2116 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
377 -
6.8
MEDIUM Unspecified vulnerability in the Oracle Text component in Oracle Database 9.0.1.5+ and 9.2.0.5 has unknown impact and attack vectors, aka DB12. NOTE: as of 20070424, Oracle has not disputed reliable… NVD-CWE-noinfo
CVE-2007-2117 cpe:2.3:a:oracle:database_server:9.2.0.5:* 2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
378 -
7.5
HIGH Unspecified vulnerability in the Upgrade/Downgrade component of Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors, aka DB13. NOTE: as of 20070424, Oracle has not disputed rel… NVD-CWE-noinfo
CVE-2007-2118 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
379 -
6.8
MEDIUM Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in… NVD-CWE-Other
CVE-2007-2119 cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database_server:10.2.0.2:*
cpe:2.3:a:oracle:database_…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm
380 -
9.0
HIGH Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Busine… NVD-CWE-Other
CVE-2007-2130 cpe:2.3:a:oracle:database_server:9.2.0.1:*
cpe:2.3:a:oracle:database_server:10.2.0.1:*
cpe:2.3:a:oracle:database_…
2026-04-23 09:35
2007-04-19
Show GitHub Exploit DB Packet Storm