Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-1363


Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.


Published

2004-08-04T04:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-131

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle application_server * Yes
Application oracle application_server 9.0.2 Yes
Application oracle application_server 9.0.2.0.0 Yes
Application oracle application_server 9.0.2.0.1 Yes
Application oracle application_server 9.0.2.1 Yes
Application oracle application_server 9.0.2.2 Yes
Application oracle application_server 9.0.2.3 Yes
Application oracle application_server 9.0.3 Yes
Application oracle application_server 9.0.3.1 Yes
Application oracle application_server 9.0.4 Yes
Application oracle application_server 9.0.4.0 Yes
Application oracle application_server 9.0.4.1 Yes
Application oracle collaboration_suite - Yes
Application oracle database_server 8.1.7.4 Yes
Application oracle database_server 9.0.1.4 Yes
Application oracle database_server 9.0.1.5 Yes
Application oracle database_server 9.0.4 Yes
Application oracle database_server 9.2.0.4 Yes
Application oracle database_server 9.2.0.5 Yes
Application oracle database_server 10.1.0.2 Yes
Application oracle e-business_suite 11.5.1 Yes
Application oracle e-business_suite 11.5.2 Yes
Application oracle e-business_suite 11.5.3 Yes
Application oracle e-business_suite 11.5.4 Yes
Application oracle e-business_suite 11.5.5 Yes
Application oracle e-business_suite 11.5.6 Yes
Application oracle e-business_suite 11.5.7 Yes
Application oracle e-business_suite 11.5.8 Yes
Application oracle e-business_suite 11.5.9 Yes
Application oracle enterprise_manager 9 Yes
Application oracle enterprise_manager 9.0.1 Yes
Application oracle enterprise_manager_database_control 10.1.2 Yes
Application oracle enterprise_manager_grid_control 10.1.0.2 Yes

References