CVE-2003-0095
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 13.11% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- oracle/database server · oracle/oracle8i · oracle/oracle9i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=104549693426042&w=2
- http://otn.oracle.com/deploy/security/pdf/2003alert51.pdfPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2003-05.htmlThird Party Advisory, US Government Resource
- http://www.ciac.org/ciac/bulletins/n-046.shtml
- http://www.iss.net/security_center/static/11328.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/953746US Government Resource
- http://www.osvdb.org/6319
- http://www.securityfocus.com/bid/6849
- http://marc.info/?l=bugtraq&m=104549693426042&w=2
- http://otn.oracle.com/deploy/security/pdf/2003alert51.pdfPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2003-05.htmlThird Party Advisory, US Government Resource
- http://www.ciac.org/ciac/bulletins/n-046.shtml
- http://www.iss.net/security_center/static/11328.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/953746US Government Resource
- http://www.osvdb.org/6319
- http://www.securityfocus.com/bid/6849
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.