Vulnerability Details CVE-2003-0222
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.125
EPSS Ranking 93.5%
CVSS Severity
CVSS v2 Score 9.0
Products affected by CVE-2003-0222
-
cpe:2.3:a:oracle:database_server:7.3.3
-
cpe:2.3:a:oracle:database_server:7.3.4
-
cpe:2.3:a:oracle:database_server:8.0.1
-
cpe:2.3:a:oracle:database_server:8.0.2
-
cpe:2.3:a:oracle:database_server:8.0.3
-
cpe:2.3:a:oracle:database_server:8.0.4
-
cpe:2.3:a:oracle:database_server:8.0.5
-
cpe:2.3:a:oracle:database_server:8.0.5.1
-
cpe:2.3:a:oracle:database_server:8.0.6
-
cpe:2.3:a:oracle:database_server:8.1.5
-
cpe:2.3:a:oracle:database_server:8.1.6
-
cpe:2.3:a:oracle:database_server:8.1.7
-
cpe:2.3:a:oracle:database_server:9.2.1
-
cpe:2.3:a:oracle:database_server:9.2.2
-
cpe:2.3:a:oracle:oracle8i:8.0.6
-
cpe:2.3:a:oracle:oracle8i:8.0.6.3
-
cpe:2.3:a:oracle:oracle8i:8.0x
-
cpe:2.3:a:oracle:oracle8i:8.1.5
-
cpe:2.3:a:oracle:oracle8i:8.1.6
-
cpe:2.3:a:oracle:oracle8i:8.1.7
-
cpe:2.3:a:oracle:oracle8i:8.1.7.1
-
cpe:2.3:a:oracle:oracle8i:8.1.7.4
-
cpe:2.3:a:oracle:oracle8i:8.1x
-
cpe:2.3:a:oracle:oracle9i:9.0
-
cpe:2.3:a:oracle:oracle9i:9.0.1
-
cpe:2.3:a:oracle:oracle9i:9.0.1.2
-
cpe:2.3:a:oracle:oracle9i:9.0.1.3
-
cpe:2.3:a:oracle:oracle9i:9.0.1.4
-
cpe:2.3:a:oracle:oracle9i:9.0.2
-
cpe:2.3:a:oracle:oracle9i:9.2.0.1
-
cpe:2.3:a:oracle:oracle9i:9.2.0.2