CVE Database
/

CVE-2003-0096

Back to search

CVE-2003-0096

Published: Feb 21, 2003

Modified: Aug 8, 2024

PUBLISHED

Description

Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#743954
third-party-advisory
x_refsource_CERT-VN
6850
vdb-entry
x_refsource_BID
VU#840666
third-party-advisory
x_refsource_CERT-VN
CA-2003-05
third-party-advisory
x_refsource_CERT
N-046
third-party-advisory
government-resource
x_refsource_CIAC
oracle-totimestamptz-bo(11327)
vdb-entry
x_refsource_XF
6847
vdb-entry
x_refsource_BID
oracle-tzoffset-bo(11326)
vdb-entry
x_refsource_XF
6848
vdb-entry
x_refsource_BID
VU#663786
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now