Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations | |||
---|---|---|---|
Name | CVE-2004-1363 | First vendor Publication | 2004-08-04 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 9.8 | ||
Base Score | 9.8 | Environmental Score | 9.8 |
impact SubScore | 5.9 | Temporal Score | 9.8 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1363 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-47 | Buffer Overflow via Parameter Expansion |
CAPEC-100 | Overflow Buffers |
CAPEC-123 | Buffer Attacks |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-131 | Incorrect Calculation of Buffer Size (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
12743 | Oracle extproc Library Environment Variable Remote Overflow |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Oracle 10g iSQLPlus login.unix connectID overflow attempt RuleID : 2704-community - Revision : 12 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle 10g iSQLPlus login.unix connectID overflow attempt RuleID : 2704 - Revision : 12 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle iSQLPlus login.uix username overflow attempt RuleID : 2703-community - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle iSQLPlus login.uix username overflow attempt RuleID : 2703 - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle iSQLPlus username overflow attempt RuleID : 2702-community - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle iSQLPlus username overflow attempt RuleID : 2702 - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle iSQLPlus sid overflow attempt RuleID : 2701-community - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | Oracle iSQLPlus sid overflow attempt RuleID : 2701 - Revision : 11 - Type : SERVER-WEBAPP |
2014-01-10 | sys.dbms_rectifier_diff.differences buffer overflow attempt RuleID : 2686-community - Revision : 9 - Type : SERVER-ORACLE |
2014-01-10 | sys.dbms_rectifier_diff.differences buffer overflow attempt RuleID : 2686 - Revision : 9 - Type : SERVER-ORACLE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-01-24 | Name : The remote web server may be affected by multiple vulnerabilities. File : oracle_application_server_pci.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 118828-04 File : solaris8_118828.nasl - Type : ACT_GATHER_INFO |
2006-11-06 | Name : The remote host is missing Sun Security Patch number 118829-04 File : solaris9_118829.nasl - Type : ACT_GATHER_INFO |
2005-01-19 | Name : The remote host has an application that is affected by multiple vulnerabilities. File : oracle_database_multiple_vulns.nasl - Type : ACT_GATHER_INFO |
2004-09-02 | Name : The remote database server is affected by multiple vulnerabilities. File : oracle_create_job_vuln.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:01 |
|
2024-11-28 12:06:20 |
|
2024-02-02 17:28:16 |
|
2021-05-04 12:02:30 |
|
2021-04-22 01:02:40 |
|
2020-05-23 00:16:00 |
|
2017-07-11 12:01:36 |
|
2016-10-18 12:01:26 |
|
2014-02-17 10:28:42 |
|
2014-01-19 21:22:23 |
|
2013-05-11 11:44:51 |
|