Oracle8i

Vendor:

First CVE: Apr 29, 1999 · Active for 27 years

46
Total CVEs
More Total CVEs than 98% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Oracle8i over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 29, 1999
27 years ago
Most Recent CVE
Feb 4, 2006
7,478 days ago

CVE Severity & Scoring

Oracle8i46 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown46 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown46 (100.0%)
User Interaction
None0 (0.0%)
Unknown46 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown46 (100.0%)

Top CVEs

Signals from CVEs in this product scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) ST
Jul 21, 200110.085NOYES
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS
Oct 11, 20026.878NOYES
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requ
Jul 3, 20022.149NONO
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Se
Jul 3, 20025.044NONO
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.
Sep 2, 20046.540NOYES
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during logi
Mar 3, 200310.038NONO
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
Aug 4, 20048.537NOYES
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argumen
Mar 3, 20039.033NONO
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
Aug 4, 20049.032NONO
Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long hel
Jul 3, 20027.530NONO

Exploit Exposure

Signals from CVEs in this product scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
21.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (46 CVEs).

Media Mentions

Signals from CVEs in this product scope (46 CVEs).

Top CNAs Publishing CVEs For Oracle8i

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
standard_8.1.7.458.74.7%00
standard_8.1.7_.4126.78.8%03
standard_8.1.7.117.54.7%00
standard_8.1.7_.1116.78.0%02
standard_8.1.7.0.017.54.7%00
standard_8.1.7_.0.0116.78.0%02
standard_8.1.7126.87.7%02
standard_8.1.6126.87.7%02
standard_8.1.5126.87.7%02
standard_8.0.6.327.54.8%00
standard_8.0.6_.3106.68.1%02
standard_8.0.6126.87.6%02
enterprise_8.1.7.458.74.7%00
enterprise_8.1.7_.4106.59.7%02
enterprise_8.1.7.1.027.56.7%00
enterprise_8.1.7_.1.0116.78.0%02
enterprise_8.1.7.0.027.56.7%00
enterprise_8.1.7_.0.0116.78.0%02
enterprise_8.1.6.1.027.56.7%00
enterprise_8.1.6_.1.0116.78.0%02