Back to Database
Status published
Critical
CVE-2004-1371
Stack-based buffer overflow in Oracle 9i and 10g allows remote...
Vulnerability Description
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1371
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.ngssoftware.com/advisories/oracle23122004J.txt
- http://marc.info/?l=bugtraq&m=110382570313035&w=2
- http://www.kb.cert.org/vuls/id/316206
- http://www.us-cert.gov/cas/techalerts/TA04-245A.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18666
- http://www.securityfocus.com/bid/10871
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
More from oracle
View All →CVE-2021-3314
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A...
Medium
6.1
CVE-2020-9315
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web...
High
7.5
CVE-2020-9314
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web...
Medium
4.8
CVE-2019-2413
Vulnerability in the Oracle Reports Developer component of Oracle Fusion...
Medium
6.1
CVE-2018-3209
Vulnerability in the Java SE component of Oracle Java SE...
High
8.3
Affected Vendor
oracle
View all reports →Affected Software
application server, collaboration suite, database server, e-business suite, enterprise manager, enterprise manager database control, enterprise manager grid control, oracle10g, oracle8i, oracle9i
Vulnerable Versions:
9.0.2, 9.0.2.0.0, 9.0.2.0.1, 9.0.2.1, 9.0.2.2, 9.0.2.3, 9.0.3, 9.0.3.1, 9.0.4, 9.0.4.0, 9.0.4.1, release_1, 9i_application_server, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 9, 9.0.1, 10.1.2, 10.1.0.2, enterprise_9.0.4_.0, enterprise_10.1.0.2, personal_9.0.4_.0, personal_10.1_.0.2, standard_9.0.4_.0, standard_10.1_.0.2, enterprise_8.0.5_.0.0, enterprise_8.0.6_.0.0, enterprise_8.0.6_.0.1, enterprise_8.1.5_.0.0, enterprise_8.1.5_.0.2, enterprise_8.1.5_.1.0, enterprise_8.1.6_.0.0, enterprise_8.1.6_.1.0, enterprise_8.1.7_.0.0, enterprise_8.1.7_.1.0, enterprise_8.1.7_.4, standard_8.0.6, standard_8.0.6_.3, standard_8.1.5, standard_8.1.6, standard_8.1.7, standard_8.1.7_.0.0, standard_8.1.7_.1, standard_8.1.7_.4, client_9.2.0.1, client_9.2.0.2, enterprise_8.1.7, enterprise_9.0.1, enterprise_9.0.1.4, enterprise_9.0.1.5, enterprise_9.2.0, enterprise_9.2.0.1, enterprise_9.2.0.2, enterprise_9.2.0.3, enterprise_9.2.0.4, enterprise_9.2.0.5, personal_8.1.7, personal_9.0.1, personal_9.0.1.4, personal_9.0.1.5, personal_9.2, personal_9.2.0.1, personal_9.2.0.2, personal_9.2.0.3, personal_9.2.0.4, personal_9.2.0.5, standard_9.0, standard_9.0.1, standard_9.0.1.2, standard_9.0.1.3, standard_9.0.1.4, standard_9.0.1.5, standard_9.0.2, standard_9.2, standard_9.2.0.1, standard_9.2.0.2, standard_9.2.0.3, standard_9.2.0.4, standard_9.2.0.5
Timeline
Official Publish:
January 19th, 2005
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.