Vulnerability Name: | CVE-2001-0499 (CCN-6758) | ||||||||
Assigned: | 2001-06-27 | ||||||||
Published: | 2001-06-27 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Network Associates, Inc. COVERT Labs Security Advisory #50, COVERT-2001-04, June 27, 2001 Vulnerability in Oracle 8i TNS Listener Source: MITRE Type: CNA CVE-2001-0499 Source: CCN Type: Oracle Technology Network Web site Buffer Overflow Vulnerability in the Oracle8i Listener Source: CCN Type: CERT Advisory CA-2001-16 Oracle 8i contains buffer overflow in TNS listener Source: CERT Type: US Government Resource CA-2001-16 Source: CCN Type: CIAC Information Bulletin L-108 Oracle 8i TNS Listener Vulnerability Source: CCN Type: US-CERT VU#620495 Oracle 8i contains buffer overflow in TNS Listener Source: CERT-VN Type: US Government Resource VU#620495 Source: NAI Type: UNKNOWN 20010627 Vulnerability in Oracle 8i TNS Listener Source: CCN Type: OSVDB ID: 9427 Oracle TNS Listener Multiple Command Long Argument Overflow Source: BID Type: UNKNOWN 2941 Source: CCN Type: BID-2941 Oracle 8i TNS Listener Buffer Overflow Vulnerability Source: XF Type: UNKNOWN oracle-tns-listener-bo(6758) Source: XF Type: UNKNOWN oracle-tns-listener-bo(6758) Source: CCN Type: Rapid7 Vulnerability and Exploit Database https://www.rapid7.com/db/modules/exploit/windows/oracle/tns_arguments | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |