CVE-2005-3438
Last modified
CVE-2005-3438 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle Label Security; (7) DB27 in Security, possibly due to a buffer overflow in sys.pbsde.init; and (8) DB28 and (9) DB29 in Workspace Manager.. EPSS estimates a 5.87% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle Label Security; (7) DB27 in Security, possibly due to a buffer overflow in sys.pbsde.init; and (8) DB28 and (9) DB29 in Workspace Manager.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Database Server | <= 10.1.0.4.2 |
References
- http://www.kb.cert.org/vuls/id/210524US Government Resource
- http://www.kb.cert.org/vuls/id/449444US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-292A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/210524US Government Resource
- http://www.kb.cert.org/vuls/id/449444US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-292A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3438?
How severe is CVE-2005-3438?
How do I fix CVE-2005-3438?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3432MiniGal 2 (MG2) 0.5.1 allows remote attackers to list passwo…
- CVE-2005-3433Buffer overflow in Mirabilis ICQ 2003a allows user-assisted …
- CVE-2005-3434Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd …
- CVE-2005-3435admin_news.php in Archilles Newsworld up to 1.3.0 allows att…9.8
- CVE-2005-3436Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 a…
- CVE-2005-3437Unspecified vulnerability in the PL/SQL component in Oracle …
- CVE-2005-3439Multiple unspecified vulnerabilities in Oracle Database Serv…
- CVE-2005-3440Unspecified vulnerability in Database Scheduler in Oracle Da…
- CVE-2005-3441Unspecified vulnerability in Intelligent Agent in Oracle Dat…
- CVE-2005-3442Multiple unspecified vulnerabilities in Oracle Database Serv…
- CVE-2005-3443Unspecified vulnerability in the Spatial component in Oracle…
- CVE-2005-3444Multiple unspecified vulnerabilities in the Programmatic Int…
Are you affected by CVE-2005-3438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
