Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
81 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
82 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
83 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
84 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
85 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
86 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
87 Oracle Database 9.0c 9.0.4 1 47 18 3
88 Oracle Database 8.0c 8.0.6.3 0 10 2 2
89 Oracle Database 7.0c 7.0.64 0 3 0 1
90 Oracle Database 5.1c 5.1 0 2 1 1
91 Oracle Database 4.0c 4.0.8 0 2 5 2
92 Oracle Database 21.3c 21.3 0 0 6 5
93 Oracle Database 10.1c 10.1.0.5 1 83 75 16
94 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
81 9.8
7.5
CRITICAL
Network
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. NVD-CWE-noinfo
CVE-2016-9843 cpe:2.3:a:oracle:database_server:18c:* 2024-11-21 12:01
2017-05-23
Show GitHub Exploit DB Packet Storm
82 8.8
6.8
HIGH
Network
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. NVD-CWE-noinfo
CVE-2016-9842 cpe:2.3:a:oracle:database_server:18c:* 2024-11-21 12:01
2017-05-23
Show GitHub Exploit DB Packet Storm
83 9.8
7.5
CRITICAL
Network
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. NVD-CWE-noinfo
CVE-2016-9841 cpe:2.3:a:oracle:database_server:18c:* 2024-11-21 12:01
2017-05-23
Show GitHub Exploit DB Packet Storm
84 3.3
2.1
LOW
Local
Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Loc… CWE-200
Information Exposure
CVE-2017-3240 cpe:2.3:a:oracle:database_server:12.1.0.2:* 2024-11-21 12:25
2017-01-28
Show GitHub Exploit DB Packet Storm
85 9.1
6.5
CRITICAL
Network
Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality, integrity, and availability via unknown vectors. NVD-CWE-noinfo
CVE-2016-5555 cpe:2.3:a:oracle:database_server:12.1.0.2:*
cpe:2.3:a:oracle:database_server:11.2.0.4:*
2024-11-21 11:54
2016-10-25
Show GitHub Exploit DB Packet Storm
86 6.0
4.7
MEDIUM
Local
Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect availability via unknown vectors. NVD-CWE-noinfo
CVE-2016-5516 cpe:2.3:a:oracle:database_server:12.1.0.2:* 2024-11-21 11:54
2016-10-25
Show GitHub Exploit DB Packet Storm
87 5.5
2.1
MEDIUM
Local
Unspecified vulnerability in the RDBMS Programmable Interface component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect confidentiality via unknown vectors. CWE-200
Information Exposure
CVE-2016-5505 cpe:2.3:a:oracle:database_server:12.1.0.2:*
cpe:2.3:a:oracle:database_server:11.2.0.4:*
2024-11-21 11:54
2016-10-25
Show GitHub Exploit DB Packet Storm
88 3.3
2.1
LOW
Local
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect confidentiality via unknown vectors, a different vulnerability t… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-5499 cpe:2.3:a:oracle:database_server:12.1.0.2:*
cpe:2.3:a:oracle:database_server:11.2.0.4:*
2024-11-21 11:54
2016-10-25
Show GitHub Exploit DB Packet Storm
89 3.3
2.1
LOW
Local
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect confidentiality via unknown vectors, a different vulnerability t… CWE-200
Information Exposure
CVE-2016-5498 cpe:2.3:a:oracle:database_server:12.1.0.2:*
cpe:2.3:a:oracle:database_server:11.2.0.4:*
2024-11-21 11:54
2016-10-25
Show GitHub Exploit DB Packet Storm
90 2.4
4.3
LOW
Network
Unspecified vulnerability in the RDBMS Security and SQL*Plus components in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality via vectors related to D… CWE-200
Information Exposure
CVE-2016-3562 cpe:2.3:a:oracle:database_server:12.1.0.2:*
cpe:2.3:a:oracle:database_server:11.2.0.4:*
2024-11-21 11:50
2016-10-25
Show GitHub Exploit DB Packet Storm