9
CVE-2004-1371
- EPSS 10.77%
- Veröffentlicht 04.08.2004 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:34
- Erkennungen
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Application Server Version 9.0.2
Oracle ≫ Application Server Version 9.0.2.0.0
Oracle ≫ Application Server Version 9.0.2.0.1
Oracle ≫ Application Server Version 9.0.2.1
Oracle ≫ Application Server Version 9.0.2.2
Oracle ≫ Application Server Version 9.0.2.3
Oracle ≫ Application Server Version 9.0.3
Oracle ≫ Application Server Version 9.0.3.1
Oracle ≫ Application Server Version 9.0.4
Oracle ≫ Application Server Version 9.0.4.0
Oracle ≫ Application Server Version 9.0.4.1
Oracle ≫ Collaboration Suite Version release_1
Oracle ≫ Database Server Version 9i_application_server
Oracle ≫ E-business Suite Version 11.5.1
Oracle ≫ E-business Suite Version 11.5.2
Oracle ≫ E-business Suite Version 11.5.3
Oracle ≫ E-business Suite Version 11.5.4
Oracle ≫ E-business Suite Version 11.5.5
Oracle ≫ E-business Suite Version 11.5.6
Oracle ≫ E-business Suite Version 11.5.7
Oracle ≫ E-business Suite Version 11.5.8
Oracle ≫ E-business Suite Version 11.5.9
Oracle ≫ Enterprise Manager Version 9
Oracle ≫ Enterprise Manager Version 9.0.1
Oracle ≫ Enterprise Manager Database Control Version 10.1.2
Oracle ≫ Enterprise Manager Grid Control Version 10.1.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.77% | 0.953 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf
http://www.securityfocus.com/bid/10871
http://www.us-cert.gov/cas/techalerts/TA04-245A.html
http://www.kb.cert.org/vuls/id/316206
http://marc.info/?l=bugtraq&m=110382570313035&w=2
http://www.ngssoftware.com/advisories/oracle23122004J.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/18666