Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Oracle Database Number Of NVD 492 CRITICAL 13 HIGH 171 MEDIUM 245 LOW 63
URL https://www.oracle.com/database/
Explanation It is a commercial relational database management system (RDBMS) developed and marketed by Oracle (USA).
It was the first commercial database released in 1979.
It has users all over the world and has all the necessary functions for a relational database management system (RDBMS).

There are three support stages for Oracle enterprise Database.

Premier Support (standard support for five years from the time of product shipment)
Extended Support (3 years of extended support from the end of Premier Support)
Extended Support (3 years of extended support after Premier Support expires) ・Sustaining Support (support received for continued use of the product)

From Oracle Database 18c onwards, the "annual release" model has been adopted.
Updates and Revisions are released in January, April, July, and October.
In the case of version "18.0.1", 18 is the version, 0 is the update, and 1 is the revision.
Tag
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.oracle.com/technetwork/jp/database/enterprise-edition/downloads/index.html
2 https://support.oracle.com/knowledge/Oracle%20Database%20Products/2413744_1.html
3 https://support.oracle.com/knowledge/Oracle%20Cloud/2413744_1.html
4 https://www.oracle.com/jp/support/lifetime-support/
5 https://www.oracle.com/jp/database/technologies/oracle-database-software-downloads.html
6 http://otndnld.oracle.co.jp/ondemand/technight/19-1_CoreInstUpgr_DL_final.pdf

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
311 Oracle Database 19c 19.5 March 31, 2023 March 31, 2026 3 9 21 10
312 Oracle Database 12c Release 2 12.2.0.1 Nov. 20, 2020 8 13 24 12
313 Oracle Database 18c 18.0.0.0 June 15, 2018 Feb. 1, 2018 9 14 23 10
314 Oracle Database 12c Release 1 12.1.0.2 July 1, 2013 Aug. 31, 2016 6 28 72 23
315 Oracle Database 11g Release 2 11.2.0.4 Sept. 1, 2009 Jan. 31, 2015 Dec. 31, 2020 5 40 110 27
316 Oracle Database 11g Release 1 11.1.0.7 Sept. 1, 2007 Aug. 31, 2012 Aug. 31, 2015 0 37 114 23
317 Oracle Database 9.0c 9.0.4 1 47 18 3
318 Oracle Database 8.0c 8.0.6.3 0 10 2 2
319 Oracle Database 7.0c 7.0.64 0 3 0 1
320 Oracle Database 5.1c 5.1 0 2 1 1
321 Oracle Database 4.0c 4.0.8 0 2 5 2
322 Oracle Database 21.3c 21.3 0 0 6 5
323 Oracle Database 10.1c 10.1.0.5 1 83 75 16
324 Oracle Database 1.0c 1.0.2.2 0 2 3 2
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
311 -
7.5
HIGH Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity,… NVD-CWE-noinfo
CVE-2009-1019 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-07-15
Show GitHub Exploit DB Packet Storm
312 -
4.0
MEDIUM Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors. NVD-CWE-noinfo
CVE-2009-1015 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-07-15
Show GitHub Exploit DB Packet Storm
313 -
5.5
MEDIUM Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown … NVD-CWE-noinfo
CVE-2009-0987 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-07-15
Show GitHub Exploit DB Packet Storm
314 -
4.0
MEDIUM Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL. NVD-CWE-noinfo
CVE-2009-0997 cpe:2.3:a:oracle:database_server:11.1.0.6:* 2026-04-23 09:35
2009-04-15
Show GitHub Exploit DB Packet Storm
315 -
6.5
MEDIUM Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect co… NVD-CWE-noinfo
CVE-2009-0972 cpe:2.3:a:oracle:database_server:9.2.0.8dv:*
cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database…
2026-04-23 09:35
2009-04-15
Show GitHub Exploit DB Packet Storm
316 -
5.1
MEDIUM Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated us… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-6065 cpe:2.3:a:oracle:database_server:11:*
cpe:2.3:a:oracle:database_server:10.2:*
cpe:2.3:a:oracle:database_server:10…
2026-04-23 09:35
2009-02-5
Show GitHub Exploit DB Packet Storm
317 -
1.5
LOW Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and local attack vectors. NVD-CWE-noinfo
CVE-2008-2587 cpe:2.3:a:oracle:database_server:10.2.0.3:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2008-07-16
Show GitHub Exploit DB Packet Storm
318 -
3.5
LOW Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enterprise Manager 10.1.0.6 has unknown impact and remote authenticated attack vectors. NVD-CWE-noinfo
CVE-2008-2590 cpe:2.3:a:oracle:database_server:10.1.0.5:* 2026-04-23 09:35
2008-07-16
Show GitHub Exploit DB Packet Storm
319 -
6.5
MEDIUM Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors. NVD-CWE-noinfo
CVE-2008-2591 cpe:2.3:a:oracle:database_server:11.1.0.6:*
cpe:2.3:a:oracle:database_server:10.2.0.3:*
2026-04-23 09:35
2008-07-16
Show GitHub Exploit DB Packet Storm
320 -
5.5
MEDIUM Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated atta… NVD-CWE-noinfo
CVE-2008-2592 cpe:2.3:a:oracle:database_server:9.2.0.8:*
cpe:2.3:a:oracle:database_server:10.1.0.5:*
2026-04-23 09:35
2008-07-16
Show GitHub Exploit DB Packet Storm