CVE-2006-3705
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE.
Múltiples vulnerabilidades no especificadas en Oracle Database 10.1.0.5 tiene un impacto desconocido y vectores de ataque, también conocido como Oracle Vuln# (1) DB21 para Statistics y (2) DB22 para Upgrade & Downgrade. NOTA: en fecha 20060719, Oracle no ha disputado este asunto por un investigador creible que DB21 es para vulnerabildades de inyección SQL local en SYS.DBMS_STATS, y que DB22 es para inyección SQL en SYS.DBMS_UPGRADE.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-18 CVE Reserved
- 2006-07-19 CVE Published
- 2024-01-29 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (20)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.red-database-security.com/advisory/oracle_cpu_july_2006.html | 2018-10-18 | |
http://www.securityfocus.com/bid/19054 | 2018-10-18 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21111 | 2018-10-18 | |
http://secunia.com/advisories/21165 | 2018-10-18 | |
http://www.securityfocus.com/archive/1/440758/100/100/threaded | 2018-10-18 | |
http://www.vupen.com/english/advisories/2006/2863 | 2018-10-18 | |
http://www.vupen.com/english/advisories/2006/2947 | 2018-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Database Server Search vendor "Oracle" for product "Database Server" | 10.1.0.5 Search vendor "Oracle" for product "Database Server" and version "10.1.0.5" | - |
Affected
|