Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
2004-08-04T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv3.1: 9.8 (CRITICAL)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | oracle | application_server | * | Yes |
Application | oracle | application_server | 9.0.2 | Yes |
Application | oracle | application_server | 9.0.2.0.0 | Yes |
Application | oracle | application_server | 9.0.2.0.1 | Yes |
Application | oracle | application_server | 9.0.2.1 | Yes |
Application | oracle | application_server | 9.0.2.2 | Yes |
Application | oracle | application_server | 9.0.2.3 | Yes |
Application | oracle | application_server | 9.0.3 | Yes |
Application | oracle | application_server | 9.0.3.1 | Yes |
Application | oracle | application_server | 9.0.4 | Yes |
Application | oracle | application_server | 9.0.4.0 | Yes |
Application | oracle | application_server | 9.0.4.1 | Yes |
Application | oracle | collaboration_suite | - | Yes |
Application | oracle | database_server | 8.1.7.4 | Yes |
Application | oracle | database_server | 9.0.1.4 | Yes |
Application | oracle | database_server | 9.0.1.5 | Yes |
Application | oracle | database_server | 9.0.4 | Yes |
Application | oracle | database_server | 9.2.0.4 | Yes |
Application | oracle | database_server | 9.2.0.5 | Yes |
Application | oracle | database_server | 10.1.0.2 | Yes |
Application | oracle | e-business_suite | 11.5.1 | Yes |
Application | oracle | e-business_suite | 11.5.2 | Yes |
Application | oracle | e-business_suite | 11.5.3 | Yes |
Application | oracle | e-business_suite | 11.5.4 | Yes |
Application | oracle | e-business_suite | 11.5.5 | Yes |
Application | oracle | e-business_suite | 11.5.6 | Yes |
Application | oracle | e-business_suite | 11.5.7 | Yes |
Application | oracle | e-business_suite | 11.5.8 | Yes |
Application | oracle | e-business_suite | 11.5.9 | Yes |
Application | oracle | enterprise_manager | 9 | Yes |
Application | oracle | enterprise_manager | 9.0.1 | Yes |
Application | oracle | enterprise_manager_database_control | 10.1.2 | Yes |
Application | oracle | enterprise_manager_grid_control | 10.1.0.2 | Yes |