← Vulnerability feed

Vulnerability record · CVE-2001-0499 · published 21 July 2001

CVE-2001-0499: Oracle 8i TNS Listener buffer overflow via command arguments

Oracle · Oracle8i

The Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier contains a buffer overflow reachable through long arguments to the STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG, and RELOAD commands. A remote, unauthenticated attacker can trigger it over the network, and the flaw is severe because it can yield full control of the listener process.

10.0 CVSS 2.0 High EPSS 85% · top 0.3%
10.0CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus very high EPSS, makes this a top-priority exposure despite the absence of KEV listing.

What it is

The Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier contains a buffer overflow reachable through long arguments to the STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG, and RELOAD commands. A remote, unauthenticated attacker can trigger it over the network, and the flaw is severe because it can yield full control of the listener process.

Impact

An attacker gains the privileges of the TNS Listener process, which on Oracle installations typically runs with high system rights, enabling arbitrary code execution and potential full compromise of the database host.

Attack surface

Reachable over the network via the TNS Listener service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The description does not specify the default port or whether the listener must be exposed, so exposure depends on deployment.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.852 probability, 99.7th percentile), indicating substantial observed exploitation likelihood. Reference tags are limited to US Government Resource and generic advisory links, with no public exploit tag supplied.

What to do

  • Apply the Oracle patch or upgrade past 8i 8.1.7; this is the only complete fix.
  • Restrict network access to the TNS Listener port with firewall rules and allow only trusted hosts.
  • Disable or remove the listener's administrative commands where they are not needed, and run the listener under a least-privilege account.
  • Monitor Oracle security advisories and CERT/CC guidance for interim workarounds if patching is delayed.

Detection

  • Inspect TNS Listener logs for unusually long arguments or malformed commands such as STATUS, PING, SERVICES, TRC_FILE, SAVE_CONFIG, and RELOAD.
  • Alert on listener process crashes, restarts, or unexpected child processes.
  • Monitor network traffic to the listener port for oversized or anomalous command payloads.
  • Correlate host process creation events from the listener with unexpected binaries or shell activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-0262Oracle database server vulnerabilityUnspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has u…EPSS 3.9%10.0CVE-2006-0271Oracle database server vulnerabilityUnspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impa…EPSS 3.4%10.0CVE-2003-0095Oracle database server memory buffer overflow vulnerabilityBuffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long userna…EPSS 13%9.0CVE-2004-1371Oracle application server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…EPSS 11%9.0CVE-2003-0222Oracle database server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via…EPSS 11%9.0CVE-2003-0096Oracle database server memory buffer overflow vulnerabilityMultiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a…EPSS 16%8.5CVE-2004-0638Oracle8i memory buffer overflow vulnerabilityBuffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, …EPSS 6.6%8.5CVE-2004-1364Oracle application server path traversal vulnerabilityDirectory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\b…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2001-0499), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.