CVE-2004-0638
Last modified
CVE-2004-0638 is a vulnerability of currently unknown severity. Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.. EPSS estimates a 6.63% chance of exploitation in the next 30 days.
Description
Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle8i | enterprise_8.1.7.4 |
| Oracle | Oracle8i | standard_8.1.7.4 |
| Oracle | Oracle9i | enterprise_9.0.1.4 |
| Oracle | Oracle9i | enterprise_9.0.1.5 |
| Oracle | Oracle9i | enterprise_9.2.0.3 |
| Oracle | Oracle9i | enterprise_9.2.0.4 |
| Oracle | Oracle9i | personal_9.0.1.4 |
| Oracle | Oracle9i | personal_9.0.1.5 |
| Oracle | Oracle9i | personal_9.2.0.3 |
| Oracle | Oracle9i | personal_9.2.0.4 |
| Oracle | Oracle9i | standard_9.0.1.4 |
| Oracle | Oracle9i | standard_9.0.1.5 |
| Oracle | Oracle9i | standard_9.2.0.3 |
| Oracle | Oracle9i | standard_9.2.0.4 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0178.htmlPatch, Vendor Advisory
- http://www.red-database-security.com/advisory/advisory_20040903_3.htmPatch, Vendor Advisory
- http://archives.neohapsis.com/archives/fulldisclosure/2004-09/0178.htmlPatch, Vendor Advisory
- http://www.red-database-security.com/advisory/advisory_20040903_3.htmPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0638?
How severe is CVE-2004-0638?
How do I fix CVE-2004-0638?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0632Adobe Reader 6.0 does not properly handle null characters wh…
- CVE-2004-0633The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows…
- CVE-2004-0634The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4…
- CVE-2004-0635The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows …
- CVE-2004-0636Buffer overflow in the goaway function in the aim:goaway URI…
- CVE-2004-0637Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local …
- CVE-2004-0639Multiple cross-site scripting (XSS) vulnerabilities in Squir…
- CVE-2004-0640Format string vulnerability in the SSL_set_verify function i…
- CVE-2004-0641Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270…
- CVE-2004-0642Double free vulnerabilities in the error handling code for A…
- CVE-2004-0643Double free vulnerability in the krb5_rd_cred function for M…
- CVE-2004-0644The asn1buf_skiptail function in the ASN.1 decoder library f…
Are you affected by CVE-2004-0638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
