Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
431 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
432 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
433 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
434 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
435 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
436 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
437 Oracle Database 9.0c 9.0.4 1 47 18 3
438 Oracle Database 8.0c 8.0.6.3 0 10 2 2
439 Oracle Database 7.0c 7.0.64 0 3 0 1
440 Oracle Database 5.1c 5.1 0 2 1 1
441 Oracle Database 4.0c 4.0.8 0 2 5 2
442 Oracle Database 21.3c 21.3 0 0 6 5
443 Oracle Database 10.1c 10.1.0.5 1 83 75 16
444 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
431 -
7.5
HIGH Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privil… NVD-CWE-Other
CVE-2006-0547 cpe:2.3:a:oracle:database_server:9.2.0.7:r2
cpe:2.3:a:oracle:database_server:9.2.0.6:r2
cpe:2.3:a:oracle:database…
2017-07-20 10:29
2006-02-4
Show GitHub Exploit DB Packet Storm
432 -
7.5
HIGH SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOT… NVD-CWE-Other
CVE-2006-0548 cpe:2.3:a:oracle:database_server:10.1.0.4.2:r1 2017-07-20 10:29
2006-02-4
Show GitHub Exploit DB Packet Storm
433 -
7.5
HIGH SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vec… NVD-CWE-Other
CVE-2006-0549 cpe:2.3:a:oracle:database_server:10.1.0.5:r1 2017-07-20 10:29
2006-02-4
Show GitHub Exploit DB Packet Storm
434 -
7.5
HIGH SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to… NVD-CWE-Other
CVE-2006-0551 cpe:2.3:a:oracle:database_server:10.2.0.1:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
cpe:2.3:a:oracle:database…
2017-07-20 10:29
2006-02-4
Show GitHub Exploit DB Packet Storm
435 -
10.0
HIGH Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01. NVD-CWE-noinfo
CVE-2006-0256 cpe:2.3:a:oracle:database_server:9.2.0.6:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2012-10-23 10:56
2006-01-18
Show GitHub Exploit DB Packet Storm
436 -
10.0
HIGH Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.… NVD-CWE-noinfo
CVE-2006-0257 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:10.2.0.1:*
cpe:2.3:a:oracle:database_…
2017-07-20 10:29
2006-01-18
Show GitHub Exploit DB Packet Storm
437 -
10.0
HIGH Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03. NVD-CWE-noinfo
CVE-2006-0258 cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_server:8.1.7.4:*
2017-07-20 10:29
2006-01-18
Show GitHub Exploit DB Packet Storm
438 -
10.0
HIGH Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictio… NVD-CWE-noinfo
CVE-2006-0261 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2018-10-20 00:43
2006-01-18
Show GitHub Exploit DB Packet Storm
439 -
10.0
HIGH Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identifie… NVD-CWE-noinfo
CVE-2006-0262 cpe:2.3:a:oracle:database_server:8.1.7.4:* 2017-07-20 10:29
2006-01-18
Show GitHub Exploit DB Packet Storm
440 -
10.0
HIGH Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln… NVD-CWE-noinfo
CVE-2006-0263 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.0.1.5:*
cpe:2.3:a:oracle:database_s…
2017-07-20 10:29
2006-01-18
Show GitHub Exploit DB Packet Storm