Oracle9i

Vendor:

First CVE: Jul 21, 2001 · Active for 25 years

52
Total CVEs
More Total CVEs than 98% of tracked products
8.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Oracle9i over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2001
25 years ago
Most Recent CVE
Dec 23, 2006
7,157 days ago

CVE Severity & Scoring

Oracle9i52 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown52 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown52 (100.0%)
User Interaction
None0 (0.0%)
Unknown52 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown52 (100.0%)

Top CVEs

Signals from CVEs in this product scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter
Oct 4, 20027.579NOYES
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS
Oct 11, 20026.878NOYES
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requ
Jul 3, 20022.149NONO
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Se
Jul 3, 20025.044NONO
Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.
Sep 2, 20046.540NOYES
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during logi
Mar 3, 200310.038NONO
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
Aug 4, 20048.537NOYES
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argumen
Mar 3, 20039.033NONO
Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing lon
Dec 3, 200410.032NONO
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
Aug 4, 20049.032NONO

Exploit Exposure

Signals from CVEs in this product scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
13.5% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (52 CVEs).

Media Mentions

Signals from CVEs in this product scope (52 CVEs).

Top CNAs Publishing CVEs For Oracle9i

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
standard_9.2.345.37.1%02
standard_9.2.0.747.23.6%00
standard_9.2.0.656.36.9%01
standard_9.2.0.5126.18.7%02
standard_9.2.0.4146.49.1%04
standard_9.2.0.3146.38.1%03
standard_9.2.0.2166.48.1%03
standard_9.2.0.1166.48.1%03
standard_9.2146.48.6%03
standard_9.0.425.912.7%01
standard_9.0.2.417.54.7%00
standard_9.0.2156.78.5%03
standard_9.0.1.5_fips25.912.7%01
standard_9.0.1.5136.78.7%03
standard_9.0.1.4176.78.1%03
standard_9.0.1.3166.79.1%04
standard_9.0.1.2156.78.5%03
standard_9.0.1156.78.5%03
standard_9.0156.78.5%03
standard_8.1.7106.68.3%01