VulnerabilityModified
CVE-2006-1868
Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03.
HIGH 7.5EPSS 12.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 12.06% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- oracle/database server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19712Vendor Advisory
- http://secunia.com/advisories/19859Vendor Advisory
- http://securitytracker.com/id?1015961Patch
- http://www.argeniss.com/research/ARGENISS-ADV-040603.txtVendor Advisory
- http://www.kb.cert.org/vuls/id/797465Patch, US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
- http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html
- http://www.securityfocus.com/archive/1/431588/100/0/threaded
- http://www.securityfocus.com/archive/1/432267/100/0/threaded
- http://www.securityfocus.com/bid/17590Exploit
- http://www.us-cert.gov/cas/techalerts/TA06-109A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/1397Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1571Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26049
- http://secunia.com/advisories/19712Vendor Advisory
- http://secunia.com/advisories/19859Vendor Advisory
- http://securitytracker.com/id?1015961Patch
- http://www.argeniss.com/research/ARGENISS-ADV-040603.txtVendor Advisory
- http://www.kb.cert.org/vuls/id/797465Patch, US Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html
- http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html
- http://www.securityfocus.com/archive/1/431588/100/0/threaded
- http://www.securityfocus.com/archive/1/432267/100/0/threaded
- http://www.securityfocus.com/bid/17590Exploit
- http://www.us-cert.gov/cas/techalerts/TA06-109A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/1397Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1571Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26049
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.