Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
461 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
462 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
463 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
464 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
465 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
466 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
467 Oracle Database 9.0c 9.0.4 1 47 18 3
468 Oracle Database 8.0c 8.0.6.3 0 10 2 2
469 Oracle Database 7.0c 7.0.64 0 3 0 1
470 Oracle Database 5.1c 5.1 0 2 1 1
471 Oracle Database 4.0c 4.0.8 0 2 5 2
472 Oracle Database 21.3c 21.3 0 0 6 5
473 Oracle Database 10.1c 10.1.0.5 1 83 75 16
474 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
461 -
10.0
HIGH Unspecified vulnerability in Database Scheduler in Oracle Database Server 10g up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB08. NVD-CWE-Other
CVE-2005-3440 cpe:2.3:a:oracle:database_server:10.1.0.3:* 2012-10-23 10:51
2005-11-2
Show GitHub Exploit DB Packet Storm
462 -
10.0
HIGH Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB17. NVD-CWE-Other
CVE-2005-3443 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.2.0.6:*
cpe:2.3:a:oracle:database_s…
2012-10-23 10:51
2005-11-2
Show GitHub Exploit DB Packet Storm
463 -
10.0
HIGH Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i up to 9.2.0.5 have unknown impact and attack vectors, aka Oracle Vuln# DB26. NVD-CWE-Other
CVE-2005-3444 cpe:2.3:a:oracle:database_server:9.2.0.7:*
cpe:2.3:a:oracle:database_server:9.2.0.6:*
cpe:2.3:a:oracle:database_s…
2012-10-23 10:51
2005-11-2
Show GitHub Exploit DB Packet Storm
464 -
3.5
LOW Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set ma… CWE-79
Cross-site Scripting
CVE-2005-3205 cpe:2.3:a:oracle:database_server:9.0.2.4:r2 2017-07-11 10:33
2005-10-14
Show GitHub Exploit DB Packet Storm
465 -
5.0
MEDIUM iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a … NVD-CWE-Other
CVE-2005-3206 cpe:2.3:a:oracle:database_server:9.0.2.4:* 2017-07-11 10:33
2005-10-14
Show GitHub Exploit DB Packet Storm
466 -
5.0
MEDIUM The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive … NVD-CWE-Other
CVE-2005-0298 cpe:2.3:a:oracle:database_server:9.2.0.6:*
cpe:2.3:a:oracle:database_server:9.2.0.5:*
cpe:2.3:a:oracle:database_s…
2017-07-11 10:32
2005-05-2
Show GitHub Exploit DB Packet Storm
467 -
7.5
HIGH SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAM… NVD-CWE-Other
CVE-2005-1197 cpe:2.3:a:oracle:database_server:10.1.0.4:*
cpe:2.3:a:oracle:database_server:10.1.0.3:*
cpe:2.3:a:oracle:database…
2016-10-18 12:18
2005-05-2
Show GitHub Exploit DB Packet Storm
468 -
7.5
HIGH SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges. NVD-CWE-Other
CVE-2005-0297 cpe:2.3:a:oracle:database_server:10.2.1:r2 2016-10-18 12:09
2005-01-18
Show GitHub Exploit DB Packet Storm
469 -
6.5
MEDIUM Unknown multiple vulnerabilities in Oracle9i Database Server 9.0.1.4, 9.0.1.5, 9.2.0.3, and 9.2.0.4 allow local users with the ability to invoke SQL to cause a denial of service or obtain sensitive i… NVD-CWE-noinfo
CVE-2004-2345 cpe:2.3:a:oracle:database_server:9.2.0.4:*
cpe:2.3:a:oracle:database_server:9.2.0.3:*
cpe:2.3:a:oracle:database_s…
2017-07-11 10:31
2004-12-31
Show GitHub Exploit DB Packet Storm
470 -
6.5
MEDIUM The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the … CWE-264
Permissions, Privileges, and Access Controls
CVE-2004-1338 cpe:2.3:a:oracle:database_server:10.2.1:r2 2017-07-11 10:30
2004-12-23
Show GitHub Exploit DB Packet Storm