CVE-2002-0857
high · 7.5Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
7.5
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2002-09-05
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| oracle | database_server | 7.3.4 |
| oracle | database_server | 9.0 |
| oracle | database_server | 9.2 |
| oracle | oracle8i | 8.1 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=102933735716634&w=2
- http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf
- http://securitytracker.com/id?1005037
- http://www.kb.cert.org/vuls/id/301059
- http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt
- http://www.securityfocus.com/bid/5460
- http://marc.info/?l=bugtraq&m=102933735716634&w=2
- http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf
- http://securitytracker.com/id?1005037
- http://www.kb.cert.org/vuls/id/301059
- http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt
- http://www.securityfocus.com/bid/5460
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0857