Vulnerability Name: | CVE-2006-1868 (CCN-26049) | ||||||||
Assigned: | 2006-04-18 | ||||||||
Published: | 2006-04-18 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 18 2006 - 14:04:23 CDT Multiple critical and high risk issues in Oracle's database server Source: CCN Type: Full-Disclosure Mailing List, Wed Apr 19 2006 - 19:02:56 CDT [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure Source: MITRE Type: CNA CVE-2006-1868 Source: CCN Type: SA19712 Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 19712 Source: CCN Type: SA19859 HP Oracle for OpenView Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 19859 Source: CCN Type: SECTRACK ID: 1015961 Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: Patch 1015961 Source: MISC Type: Vendor Advisory http://www.argeniss.com/research/ARGENISS-ADV-040603.txt Source: CCN Type: US-CERT VU#797465 Oracle Advanced Replication SQL injection vulnerability Source: CERT-VN Type: Patch, US Government Resource VU#797465 Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - April 2006 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html Source: CCN Type: Red-Database-Security Web site Details Oracle Critical Patch Update April 2006 - V1.03 Source: MISC Type: UNKNOWN http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html Source: BUGTRAQ Type: UNKNOWN 20060420 [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure Source: HP Type: UNKNOWN SSRT061148 Source: BID Type: Exploit 17590 Source: CCN Type: BID-17590 Oracle April 2006 Security Update Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-109A Oracle Products Contain Multiple Vulnerabilities Source: CERT Type: US Government Resource TA06-109A Source: VUPEN Type: Vendor Advisory ADV-2006-1397 Source: VUPEN Type: Vendor Advisory ADV-2006-1571 Source: XF Type: UNKNOWN oracle-dbmssnapshotutl-bo(26049) Source: XF Type: UNKNOWN oracle-dbmssnapshotutl-bo(26049) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Vulnerability Name: | CVE-2006-1868 (CCN-39381) | ||||||||
Assigned: | 2006-04-15 | ||||||||
Published: | 2006-04-15 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | Buffer overflow in the Advanced Replication component in Oracle Database Server 10.1.0.4 allows database users to execute arbitrary code via the VERIFY_LOG procedure of the DBMS_SNAPSHOT_UTL package, aka Vuln# DB03. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0435 Source: MITRE Type: CNA CVE-2006-1866 Source: MITRE Type: CNA CVE-2006-1867 Source: MITRE Type: CNA CVE-2006-1868 Source: MITRE Type: CNA CVE-2006-1869 Source: MITRE Type: CNA CVE-2006-1870 Source: MITRE Type: CNA CVE-2006-1871 Source: MITRE Type: CNA CVE-2006-1872 Source: MITRE Type: CNA CVE-2006-1873 Source: MITRE Type: CNA CVE-2006-1874 Source: MITRE Type: CNA CVE-2006-1875 Source: MITRE Type: CNA CVE-2006-1876 Source: MITRE Type: CNA CVE-2006-1877 Source: MITRE Type: CNA CVE-2006-1879 Source: MITRE Type: CNA CVE-2006-1880 Source: MITRE Type: CNA CVE-2006-1881 Source: MITRE Type: CNA CVE-2006-1882 Source: MITRE Type: CNA CVE-2006-1883 Source: MITRE Type: CNA CVE-2006-1884 Source: MITRE Type: CNA CVE-2006-1885 Source: MITRE Type: CNA CVE-2006-1886 Source: MITRE Type: CNA CVE-2006-1887 Source: CCN Type: Oracle Critical Patch Update - April 2006 Critical Patch Update - April 2006 Source: CCN Type: IBM Internet Security Systems X-Force Database Oracle PL/SQL Gateway SQL command execution Source: XF Type: UNKNOWN oracle-cpu-apr2006(39381) | ||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||
BACK |