Oracle9i
Vendor:
First CVE: Jul 21, 2001 · Active for 25 years
52
Total CVEs
More Total CVEs than 98% of tracked products
8.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 37% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Oracle9i over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2001
25 years ago
Most Recent CVE
Dec 23, 2006
7,157 days ago
CVE Severity & Scoring
Oracle9i52 CVEs
44%
52%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown52 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown52 (100.0%)
User Interaction
None0 (0.0%)
Unknown52 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown52 (100.0%)
Top CVEs
Signals from CVEs in this product scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0965HIGH Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter | Oct 4, 2002 | 7.5 | 79 | NO | YES |
CVE-2002-0840MEDIUM Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS | Oct 11, 2002 | 6.8 | 78 | NO | YES |
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requ | Jul 3, 2002 | 2.1 | 49 | NO | NO |
CVE-2002-0563MEDIUM The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Se | Jul 3, 2002 | 5.0 | 44 | NO | NO |
CVE-2004-0637MEDIUM Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible. | Sep 2, 2004 | 6.5 | 40 | NO | YES |
CVE-2003-0095HIGH Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during logi | Mar 3, 2003 | 10.0 | 38 | NO | NO |
CVE-2004-1364HIGH Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory. | Aug 4, 2004 | 8.5 | 37 | NO | YES |
CVE-2003-0096HIGH Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argumen | Mar 3, 2003 | 9.0 | 33 | NO | NO |
CVE-2003-1208HIGH Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing lon | Dec 3, 2004 | 10.0 | 32 | NO | NO |
CVE-2004-1371HIGH Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure. | Aug 4, 2004 | 9.0 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (52 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
13.5% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (52 CVEs).
Media Mentions
Signals from CVEs in this product scope (52 CVEs).
Top CNAs Publishing CVEs For Oracle9i
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| standard_9.2.3 | 4 | 5.3 | 7.1% | 0 | 2 |
| standard_9.2.0.7 | 4 | 7.2 | 3.6% | 0 | 0 |
| standard_9.2.0.6 | 5 | 6.3 | 6.9% | 0 | 1 |
| standard_9.2.0.5 | 12 | 6.1 | 8.7% | 0 | 2 |
| standard_9.2.0.4 | 14 | 6.4 | 9.1% | 0 | 4 |
| standard_9.2.0.3 | 14 | 6.3 | 8.1% | 0 | 3 |
| standard_9.2.0.2 | 16 | 6.4 | 8.1% | 0 | 3 |
| standard_9.2.0.1 | 16 | 6.4 | 8.1% | 0 | 3 |
| standard_9.2 | 14 | 6.4 | 8.6% | 0 | 3 |
| standard_9.0.4 | 2 | 5.9 | 12.7% | 0 | 1 |
| standard_9.0.2.4 | 1 | 7.5 | 4.7% | 0 | 0 |
| standard_9.0.2 | 15 | 6.7 | 8.5% | 0 | 3 |
| standard_9.0.1.5_fips | 2 | 5.9 | 12.7% | 0 | 1 |
| standard_9.0.1.5 | 13 | 6.7 | 8.7% | 0 | 3 |
| standard_9.0.1.4 | 17 | 6.7 | 8.1% | 0 | 3 |
| standard_9.0.1.3 | 16 | 6.7 | 9.1% | 0 | 4 |
| standard_9.0.1.2 | 15 | 6.7 | 8.5% | 0 | 3 |
| standard_9.0.1 | 15 | 6.7 | 8.5% | 0 | 3 |
| standard_9.0 | 15 | 6.7 | 8.5% | 0 | 3 |
| standard_8.1.7 | 10 | 6.6 | 8.3% | 0 | 1 |