← All CVEs

CVE-2002-0857

high · 7.5

Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.

7.5
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2002-09-05
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
oracledatabase_server7.3.4
oracledatabase_server9.0
oracledatabase_server9.2
oracleoracle8i8.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0857