Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (crash) or read potentially sensitive memory via a connect GIOP packet with an invalid data size, which triggers a buffer over-read, aka DB22.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle Database Oracle Net Services组件GIOP服务缓冲区溢出和信息泄露漏洞
Vulnerability Description
Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 和10.2.0.3版本的Oracle Net Services组件的TNS Listener的GIOP服务允许远程攻击者,可以借助一个 GIOP 信息包和一个无效信息尺寸相连接, 且能触发缓冲区重写,以造成拒绝服务(崩溃)或读取潜在敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A