Vulnerability Name: | CVE-2006-1875 (CCN-26055) | ||||||||
Assigned: | 2006-04-18 | ||||||||
Published: | 2006-04-18 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11. Note: Oracle has not disputed reliable researcher claims that this issue is SQL injection in MDSYS.SDO_LRS_TRIG_INS. The most severe of these vulnerabilities could possibly expose affected computers to complete compromise. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 18 2006 - 14:04:23 CDT Multiple critical and high risk issues in Oracle's database server Source: MITRE Type: CNA CVE-2006-1875 Source: CCN Type: SA19712 Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 19712 Source: CCN Type: SA19859 HP Oracle for OpenView Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 19859 Source: CCN Type: SECTRACK ID: 1015961 Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: Patch 1015961 Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - April 2006 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html Source: CCN Type: Red-Database-Security Web site Details Oracle Critical Patch Update April 2006 - V1.03 Source: MISC Type: UNKNOWN http://www.red-database-security.com/advisory/oracle_cpu_apr_2006.html Source: HP Type: UNKNOWN SSRT061148 Source: BID Type: Patch 17590 Source: CCN Type: BID-17590 Oracle April 2006 Security Update Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-109A Oracle Products Contain Multiple Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2006-1397 Source: VUPEN Type: Vendor Advisory ADV-2006-1571 Source: XF Type: UNKNOWN oracle-sdolrstrigins-sql-injection(26055) Source: XF Type: UNKNOWN oracle-sdolrstrigins-sql-injection(26055) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Vulnerability Name: | CVE-2006-1875 (CCN-39381) | ||||||||
Assigned: | 2006-04-15 | ||||||||
Published: | 2006-04-15 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | The most severe of these vulnerabilities could possibly expose affected computers to complete compromise. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0435 Source: MITRE Type: CNA CVE-2006-1866 Source: MITRE Type: CNA CVE-2006-1867 Source: MITRE Type: CNA CVE-2006-1868 Source: MITRE Type: CNA CVE-2006-1869 Source: MITRE Type: CNA CVE-2006-1870 Source: MITRE Type: CNA CVE-2006-1871 Source: MITRE Type: CNA CVE-2006-1872 Source: MITRE Type: CNA CVE-2006-1873 Source: MITRE Type: CNA CVE-2006-1874 Source: MITRE Type: CNA CVE-2006-1875 Source: MITRE Type: CNA CVE-2006-1876 Source: MITRE Type: CNA CVE-2006-1877 Source: MITRE Type: CNA CVE-2006-1879 Source: MITRE Type: CNA CVE-2006-1880 Source: MITRE Type: CNA CVE-2006-1881 Source: MITRE Type: CNA CVE-2006-1882 Source: MITRE Type: CNA CVE-2006-1883 Source: MITRE Type: CNA CVE-2006-1884 Source: MITRE Type: CNA CVE-2006-1885 Source: MITRE Type: CNA CVE-2006-1886 Source: MITRE Type: CNA CVE-2006-1887 Source: CCN Type: Oracle Critical Patch Update - April 2006 Critical Patch Update - April 2006 Source: CCN Type: IBM Internet Security Systems X-Force Database Oracle PL/SQL Gateway SQL command execution Source: XF Type: UNKNOWN oracle-cpu-apr2006(39381) | ||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||
BACK |