Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
391 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
392 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
393 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
394 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
395 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
396 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
397 Oracle Database 9.0c 9.0.4 1 47 18 3
398 Oracle Database 8.0c 8.0.6.3 0 10 2 2
399 Oracle Database 7.0c 7.0.64 0 3 0 1
400 Oracle Database 5.1c 5.1 0 2 1 1
401 Oracle Database 4.0c 4.0.8 0 2 5 2
402 Oracle Database 21.3c 21.3 0 0 6 5
403 Oracle Database 10.1c 10.1.0.5 1 83 75 16
404 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
391 -
6.8
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net… NVD-CWE-Other
CVE-2007-0276 cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_server:8.1.7.4:*
2026-04-23 09:35
2007-01-17
Show GitHub Exploit DB Packet Storm
392 -
6.8
MEDIUM Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11. NVD-CWE-Other
CVE-2007-0277 cpe:2.3:a:oracle:database_server:10.1.0.4:* 2026-04-23 09:35
2007-01-17
Show GitHub Exploit DB Packet Storm
393 -
6.8
MEDIUM Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Tex… NVD-CWE-Other
CVE-2007-0278 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2007-01-17
Show GitHub Exploit DB Packet Storm
394 -
9.0
HIGH Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of 200… NVD-CWE-noinfo
CVE-2006-5332 cpe:2.3:a:oracle:database_server:9.2.0.6:*
cpe:2.3:a:oracle:database_server:10.1.0.4:*
2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm
395 -
7.1
HIGH Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact and remote authenticated attack vectors related to "create session" privileges, aka Vuln# DB02. N… NVD-CWE-noinfo
CVE-2006-5333 cpe:2.3:a:oracle:database_server:10.2.0.2:* 2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm
396 -
7.1
HIGH Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and remote authenticated attack vectors related to mdsys.md2, aka Vuln# DB03… NVD-CWE-noinfo
CVE-2006-5334 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm
397 -
9.0
HIGH Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sy… NVD-CWE-noinfo
CVE-2006-5336 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:10.2.0.2:*
cpe:2.3:a:oracle:database_…
2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm
398 -
9.0
HIGH Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 has unknown impact and remote authenticated attack vectors, aka Vuln# DB09. NVD-CWE-noinfo
CVE-2006-5337 cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm
399 -
9.0
HIGH Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) Vuln# DB04 and sys.dbms_cdc_impdp in the (a) C… NVD-CWE-noinfo
CVE-2006-5335 cpe:2.3:a:oracle:database_server:10.2.0.2:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm
400 -
9.0
HIGH Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact and remote authenticated attack vectors related to sys.dbms_sqltune, aka Vuln# DB10. NOTE: as of … NVD-CWE-noinfo
CVE-2006-5338 cpe:2.3:a:oracle:database_server:10.2.0.0:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2006-10-18
Show GitHub Exploit DB Packet Storm