Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
291 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
292 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
293 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
294 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
295 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
296 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
297 Oracle Database 9.0c 9.0.4 1 47 18 3
298 Oracle Database 8.0c 8.0.6.3 0 10 2 2
299 Oracle Database 7.0c 7.0.64 0 3 0 1
300 Oracle Database 5.1c 5.1 0 2 1 1
301 Oracle Database 4.0c 4.0.8 0 2 5 2
302 Oracle Database 21.3c 21.3 0 0 6 5
303 Oracle Database 10.1c 10.1.0.5 1 83 75 16
304 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
291 -
5.5
MEDIUM Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remote authenticated users to affect confidentiality and integrity, related to FLOWS_030000.WWV_EXECUTE_… NVD-CWE-noinfo
CVE-2009-1993 cpe:2.3:a:oracle:database_server:3.0.1:* 2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
292 -
10.0
HIGH Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vec… NVD-CWE-noinfo
CVE-2009-1992 cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database_server:10.2.0.4:*
cpe:2.3:a:oracle:database_…
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
293 -
3.6
LOW Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related… NVD-CWE-noinfo
CVE-2009-1991 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
294 -
10.0
HIGH Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and avail… NVD-CWE-noinfo
CVE-2009-1985 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
295 -
10.0
HIGH Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown v… NVD-CWE-noinfo
CVE-2009-1979 cpe:2.3:a:oracle:database_server:10.2.0.4:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
296 -
2.1
LOW Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_… NVD-CWE-noinfo
CVE-2009-1972 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
297 -
3.5
LOW Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors. NVD-CWE-noinfo
CVE-2009-1971 cpe:2.3:a:oracle:database_server:11.1.0.7:*
cpe:2.3:a:oracle:database_server:10.2.0.3:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
298 -
5.4
MEDIUM Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vect… NVD-CWE-noinfo
CVE-2009-1965 cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
299 -
5.5
MEDIUM Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. NVD-CWE-noinfo
CVE-2009-1964 cpe:2.3:a:oracle:database_server:10.2.0.4:* 2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm
300 -
5.5
MEDIUM Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC). NVD-CWE-noinfo
CVE-2009-1018 cpe:2.3:a:oracle:database_server:10.2.0.4:* 2026-04-23 09:35
2009-10-23
Show GitHub Exploit DB Packet Storm