Oracle8i
Vendor:
First CVE: Apr 29, 1999 · Active for 27 years
46
Total CVEs
More Total CVEs than 98% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Oracle8i over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 29, 1999
27 years ago
Most Recent CVE
Feb 4, 2006
7,478 days ago
CVE Severity & Scoring
Oracle8i46 CVEs
43%
54%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown46 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown46 (100.0%)
User Interaction
None0 (0.0%)
Unknown46 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown46 (100.0%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0499HIGH Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) ST | Jul 21, 2001 | 10.0 | 85 | NO | YES |
CVE-2002-0840MEDIUM Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS | Oct 11, 2002 | 6.8 | 78 | NO | YES |
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requ | Jul 3, 2002 | 2.1 | 49 | NO | NO |
CVE-2002-0563MEDIUM The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Se | Jul 3, 2002 | 5.0 | 44 | NO | NO |
CVE-2004-0637MEDIUM Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible. | Sep 2, 2004 | 6.5 | 40 | NO | YES |
CVE-2003-0095HIGH Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during logi | Mar 3, 2003 | 10.0 | 38 | NO | NO |
CVE-2004-1364HIGH Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory. | Aug 4, 2004 | 8.5 | 37 | NO | YES |
CVE-2003-0096HIGH Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argumen | Mar 3, 2003 | 9.0 | 33 | NO | NO |
CVE-2004-1371HIGH Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure. | Aug 4, 2004 | 9.0 | 32 | NO | NO |
CVE-2002-0559HIGH Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long hel | Jul 3, 2002 | 7.5 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
21.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Oracle8i
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| standard_8.1.7.4 | 5 | 8.7 | 4.7% | 0 | 0 |
| standard_8.1.7_.4 | 12 | 6.7 | 8.8% | 0 | 3 |
| standard_8.1.7.1 | 1 | 7.5 | 4.7% | 0 | 0 |
| standard_8.1.7_.1 | 11 | 6.7 | 8.0% | 0 | 2 |
| standard_8.1.7.0.0 | 1 | 7.5 | 4.7% | 0 | 0 |
| standard_8.1.7_.0.0 | 11 | 6.7 | 8.0% | 0 | 2 |
| standard_8.1.7 | 12 | 6.8 | 7.7% | 0 | 2 |
| standard_8.1.6 | 12 | 6.8 | 7.7% | 0 | 2 |
| standard_8.1.5 | 12 | 6.8 | 7.7% | 0 | 2 |
| standard_8.0.6.3 | 2 | 7.5 | 4.8% | 0 | 0 |
| standard_8.0.6_.3 | 10 | 6.6 | 8.1% | 0 | 2 |
| standard_8.0.6 | 12 | 6.8 | 7.6% | 0 | 2 |
| enterprise_8.1.7.4 | 5 | 8.7 | 4.7% | 0 | 0 |
| enterprise_8.1.7_.4 | 10 | 6.5 | 9.7% | 0 | 2 |
| enterprise_8.1.7.1.0 | 2 | 7.5 | 6.7% | 0 | 0 |
| enterprise_8.1.7_.1.0 | 11 | 6.7 | 8.0% | 0 | 2 |
| enterprise_8.1.7.0.0 | 2 | 7.5 | 6.7% | 0 | 0 |
| enterprise_8.1.7_.0.0 | 11 | 6.7 | 8.0% | 0 | 2 |
| enterprise_8.1.6.1.0 | 2 | 7.5 | 6.7% | 0 | 0 |
| enterprise_8.1.6_.1.0 | 11 | 6.7 | 8.0% | 0 | 2 |