Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
481 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
482 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
483 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
484 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
485 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
486 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
487 Oracle Database 9.0c 9.0.4 1 47 18 3
488 Oracle Database 8.0c 8.0.6.3 0 10 2 2
489 Oracle Database 7.0c 7.0.64 0 3 0 1
490 Oracle Database 5.1c 5.1 0 2 1 1
491 Oracle Database 4.0c 4.0.8 0 2 5 2
492 Oracle Database 21.3c 21.3 0 0 6 5
493 Oracle Database 10.1c 10.1.0.5 1 83 75 16
494 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
481 -
7.5
HIGH Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing… NVD-CWE-Other
CVE-2002-0857 cpe:2.3:a:oracle:database_server:9.2:*
cpe:2.3:a:oracle:database_server:9.0:*
cpe:2.3:a:oracle:database_server:7.…
2016-10-18 11:22
2002-09-5
Show GitHub Exploit DB Packet Storm
482 -
7.5
HIGH Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect t… NVD-CWE-Other
CVE-2002-0567 cpe:2.3:a:oracle:database_server:8.1.7:*
cpe:2.3:a:oracle:database_server:8.1.7.0.0:*
cpe:2.3:a:oracle:database_s…
2017-10-10 10:30
2002-07-3
Show GitHub Exploit DB Packet Storm
483 -
4.6
MEDIUM Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access. NVD-CWE-Other
CVE-2001-0831 cpe:2.3:a:oracle:database_server:9.0.1:*
cpe:2.3:a:oracle:database_server:8.1.7:*
2016-10-18 11:12
2001-12-6
Show GitHub Exploit DB Packet Storm
484 -
2.1
LOW Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log direc… NVD-CWE-Other
CVE-2001-0832 cpe:2.3:a:oracle:database_server:8.1:*
cpe:2.3:a:oracle:database_server:8.0:*
cpe:2.3:a:oracle:database_server:*:*
9.0.1 2016-10-18 11:12
2001-12-6
Show GitHub Exploit DB Packet Storm
485 -
7.2
HIGH Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerabil… NVD-CWE-Other
CVE-2001-0833 cpe:2.3:a:oracle:database_server:8.1:*
cpe:2.3:a:oracle:database_server:8.0:*
cpe:2.3:a:oracle:database_server:*:*
9.0.1 2018-05-3 10:29
2001-12-6
Show GitHub Exploit DB Packet Storm
486 -
4.6
MEDIUM Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. NVD-CWE-Other
CVE-2001-0941 cpe:2.3:a:oracle:database_server:9.0.1:*
cpe:2.3:a:oracle:database_server:8.1.7:*
cpe:2.3:a:oracle:database_serve…
2017-07-11 10:29
2001-11-30
Show GitHub Exploit DB Packet Storm
487 -
4.6
MEDIUM dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME t… NVD-CWE-Other
CVE-2001-0942 cpe:2.3:a:oracle:database_server:8.1.7:*
cpe:2.3:a:oracle:database_server:8.1.6:*
2017-07-11 10:29
2001-11-29
Show GitHub Exploit DB Packet Storm
488 -
7.2
HIGH dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary… NVD-CWE-Other
CVE-2001-0943 cpe:2.3:a:oracle:database_server:8.1.5:*
cpe:2.3:a:oracle:database_server:8.0.5:*
2008-09-6 05:25
2001-08-31
Show GitHub Exploit DB Packet Storm
489 -
2.1
LOW oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory … NVD-CWE-Other
CVE-2001-1041 cpe:2.3:a:oracle:database_server:9.0.1:*
cpe:2.3:a:oracle:database_server:8.1:*
cpe:2.3:a:oracle:database_server:…
2016-10-18 11:14
2001-08-31
Show GitHub Exploit DB Packet Storm
490 -
5.0
MEDIUM Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. NVD-CWE-Other
CVE-2001-0515 cpe:2.3:a:oracle:database_server:7.3:* 2008-09-11 04:08
2001-07-21
Show GitHub Exploit DB Packet Storm