CVE-2003-1208

UnknownEPSS 13.19%

Last modified

CVE-2003-1208 is a vulnerability of currently unknown severity. Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.. EPSS estimates a 13.19% chance of exploitation in the next 30 days.

Description

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

Metrics

EPSS Probability
13.19%

95.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
OracleOracle9ienterprise_9.0.1
OracleOracle9ienterprise_9.2.0
OracleOracle9ienterprise_9.2.0.1
OracleOracle9ienterprise_9.2.0.2
OracleOracle9ipersonal_9.0.1
OracleOracle9ipersonal_9.2
OracleOracle9ipersonal_9.2.0.1
OracleOracle9ipersonal_9.2.0.2
OracleOracle9istandard_9.0
OracleOracle9istandard_9.0.1
OracleOracle9istandard_9.0.1.2
OracleOracle9istandard_9.0.1.3
OracleOracle9istandard_9.0.1.4
OracleOracle9istandard_9.0.2
OracleOracle9istandard_9.2
OracleOracle9istandard_9.2.0.1
OracleOracle9istandard_9.2.0.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2003-1208?
Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.
How severe is CVE-2003-1208?
Severity scoring for CVE-2003-1208 is pending analysis. The EPSS model estimates a 13.19% probability of exploitation in the next 30 days.
How do I fix CVE-2003-1208?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2003-1208?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST