CVE Vulnerabilities

CVE-2006-0272

Published: Jan 18, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29. NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.

Affected Software

NameVendorStart VersionEnd Version
Oracle10gOracleenterprise_10.1.0.4 (including)enterprise_10.1.0.4 (including)
Oracle10gOraclepersonal_10.1.0.4 (including)personal_10.1.0.4 (including)
Oracle10gOraclestandard_10.1.0.4 (including)standard_10.1.0.4 (including)
Oracle9iOraclestandard_9.2.0.7 (including)standard_9.2.0.7 (including)

References