Executive Summary

Informations
Name CVE-2005-3438 First vendor Publication 2005-11-02
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle Label Security; (7) DB27 in Security, possibly due to a buffer overflow in sys.pbsde.init; and (8) DB28 and (9) DB29 in Workspace Manager.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3438

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 69

SAINT Exploits

Description Link
Oracle Security Component sys.pbsde buffer overflow More info here

Open Source Vulnerability Database (OSVDB)

Id Description
20614 Oracle Database Workspace Manager sys.lt_ctx_pkg Unspecified SQL Issue

20613 Oracle Database Workspace Manager sys.lt Unspecified SQL Issue

20612 Oracle Database Security Component sys.pbsde.init Procedure Overflow

20597 Oracle Database Label Security lbacsys.lbac_session Unspecified SQL Issue

20595 Oracle Database Objects Extensions map methods Unspecified SQL Issue

20594 Oracle Database Materialized Views sys.dbms_snapshot Unspecified SQL Issue (D...

20592 Oracle Database Locale sys.utl_i18n Unspecified Trivial DoS

20588 Oracle Database Data Guard Logical Standby sys.dbms_logstdby Unspecified Tri...

20586 Oracle Database Change Data Capture sys.dbms_cdc_subscribe Unspecified Trivia...

Snort® IPS/IDS

Date Description
2014-01-10 sys.pbsde.init buffer overflow attempt
RuleID : 4642 - Revision : 8 - Type : SERVER-ORACLE

Sources (Detail)

http://lists.grok.org.uk/pipermail/full-disclosure/2005-October/038061.html
http://secunia.com/advisories/17250
http://www.kb.cert.org/vuls/id/210524
http://www.kb.cert.org/vuls/id/449444
http://www.oracle.com/technetwork/topics/security/cpuoct2005-090497.html
http://www.securityfocus.com/bid/15134
http://www.us-cert.gov/cas/techalerts/TA05-292A.html
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
Date Informations
2024-11-28 23:21:46
  • Multiple Updates
2024-11-28 12:07:34
  • Multiple Updates
2021-05-05 01:01:59
  • Multiple Updates
2021-05-04 12:03:16
  • Multiple Updates
2021-04-22 01:03:34
  • Multiple Updates
2021-02-03 01:01:44
  • Multiple Updates
2020-05-23 01:36:58
  • Multiple Updates
2020-05-23 00:16:56
  • Multiple Updates
2019-07-27 12:01:16
  • Multiple Updates
2016-04-27 09:23:38
  • Multiple Updates
2016-04-26 13:54:46
  • Multiple Updates
2014-01-19 21:22:58
  • Multiple Updates
2013-05-11 11:33:48
  • Multiple Updates