Database Server
Vendor:
First CVE: Aug 16, 1999 · Active for 26 years
521
Total CVEs
More Total CVEs than 100% of tracked products
19.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Database Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 1999
26 years ago
Most Recent CVE
May 28, 2026
57 days ago
CVE Severity & Scoring
Database Server521 CVEs
14%
50%
34%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (3.5%)
Network88 (16.9%)
Unknown414 (79.5%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low76 (14.6%)
High31 (6.0%)
Unknown414 (79.5%)
User Interaction
None72 (13.8%)
Unknown414 (79.5%)
Required35 (6.7%)
Privileges Required
Low38 (7.3%)
High39 (7.5%)
None30 (5.8%)
Unknown414 (79.5%)
Top CVEs
Signals from CVEs in this product scope (521 CVEs).
521 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1979HIGH Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availab | Oct 22, 2009 | 10.0 | 86 | NO | YES |
CVE-2010-3600HIGH Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attacke | Jan 19, 2011 | 7.5 | 80 | NO | YES |
CVE-2002-0840MEDIUM Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS | Oct 11, 2002 | 6.8 | 78 | NO | YES |
CVE-2012-1675HIGH The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager | May 8, 2012 | 7.5 | 77 | NO | YES |
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions. | Oct 20, 2003 | 2.1 | 62 | NO | YES |
CVE-2012-3137MEDIUM The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for | Sep 21, 2012 | 6.4 | 52 | NO | YES |
CVE-2007-5511MEDIUM SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via | Oct 17, 2007 | 6.5 | 51 | NO | YES |
CVE-2006-0287HIGH Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as ide | Jan 18, 2006 | 10.0 | 50 | NO | YES |
CVE-2010-0071HIGH Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integ | Jan 13, 2010 | 10.0 | 45 | NO | YES |
CVE-2008-0339HIGH Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01. | Jan 17, 2008 | 10.0 | 45 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (521 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
9 CVEs
1.7% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
5.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (521 CVEs).
Media Mentions
Signals from CVEs in this product scope (521 CVEs).
Top CNAs Publishing CVEs For Database Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| release_2 | 2 | 4.8 | 3.7% | 0 | 2 |
| 9i_application_server | 1 | 9.0 | 10.8% | 0 | 0 |
| 9.2.2 | 5 | 8.5 | 31.1% | 0 | 1 |
| 9.2.1 | 5 | 8.0 | 27.4% | 0 | 1 |
| 9.2.0.8dv | 48 | 6.5 | 3.7% | 0 | 7 |
| 9.2.0.8 | 58 | 6.4 | 3.5% | 0 | 6 |
| 9.2.0.7 | 44 | 8.4 | 4.2% | 0 | 0 |
| 9.2.0.6 | 19 | 8.9 | 4.3% | 0 | 0 |
| 9.2.0.5 | 8 | 8.8 | 4.4% | 0 | 0 |
| 9.2.0.4 | 4 | 7.5 | 4.0% | 0 | 0 |
| 9.2.0.3 | 2 | 7.5 | 2.6% | 0 | 0 |
| 9.2.0.2 | 1 | 8.5 | 3.7% | 0 | 0 |
| 9.2.0.1 | 2 | 8.8 | 3.1% | 0 | 0 |
| 9.2 | 1 | 7.5 | 13.8% | 0 | 0 |
| 9.0.4 | 2 | 7.4 | 5.5% | 0 | 0 |
| 9.0.2.4 | 2 | 4.3 | 11.6% | 0 | 1 |
| 9.0.1.5 | 60 | 8.5 | 4.2% | 0 | 1 |
| 9.0.1.4 | 4 | 7.8 | 4.1% | 0 | 0 |
| 9.0.1 | 3 | 3.8 | 0.9% | 0 | 1 |
| 9.0 | 1 | 7.5 | 13.8% | 0 | 0 |