← Vulnerability feed

Vulnerability record · CVE-2002-0965 · published 4 October 2002

CVE-2002-0965: Oracle TNS Listener SERVICE_NAME buffer overflow on Windows

Oracle · Oracle9i

The TNS Listener in Oracle 9i Database Server on Windows (and Oracle 8 on VM) mishandles a long SERVICE_NAME parameter when writing an error message to a log file, causing a buffer overflow. A local user can trigger the overflow and execute arbitrary code in the listener's context. The flaw matters because the listener is a core database component and the record provides no affected version detail beyond the product names.

7.5 CVSS 2.0 High EPSS 70% · top 0.6%
7.5CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityHigh CVSS 2.0 score and very high EPSS probability, but no confirmed exploitation and an old, narrowly scoped product set.

What it is

The TNS Listener in Oracle 9i Database Server on Windows (and Oracle 8 on VM) mishandles a long SERVICE_NAME parameter when writing an error message to a log file, causing a buffer overflow. A local user can trigger the overflow and execute arbitrary code in the listener's context. The flaw matters because the listener is a core database component and the record provides no affected version detail beyond the product names.

Impact

An attacker gains arbitrary code execution with the privileges of the TNS Listener process, which can lead to full compromise of the database host. The record does not state whether privilege escalation beyond the listener account is possible.

Attack surface

Reached through the TNS Listener service on Windows systems, per the description, via a crafted SERVICE_NAME parameter. The description says local users, while the CVSS 2.0 vector is AV:N/Au:N, so the record is internally inconsistent on whether network access and authentication are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded; EPSS is high at 0.6981 (99.3rd percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.

What to do

  • Apply the Oracle patch referenced in the vendor advisory (net9_dos_alert.pdf) and SecurityFocus BID 4845.
  • Restrict network access to the TNS Listener port to trusted hosts only.
  • Run the listener with the least privileges possible and avoid unnecessary local accounts on database hosts.
  • Monitor and rotate listener log files, and validate that SERVICE_NAME input is not logged unsafely after patching.

Detection

  • Inspect TNS Listener log files for unusually long or malformed SERVICE_NAME entries and error-message write failures.
  • Monitor for listener process crashes or restarts on Windows database hosts.
  • Alert on unexpected child processes or code execution originating from the listener process.
  • Review network connections to the listener port from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0965 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-0262Oracle database server vulnerabilityUnspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has u…EPSS 3.9%10.0CVE-2006-0271Oracle database server vulnerabilityUnspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impa…EPSS 3.4%10.0CVE-2003-1208Oracle9i vulnerabilityMultiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to…EPSS 13%10.0CVE-2003-0095Oracle database server memory buffer overflow vulnerabilityBuffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long userna…EPSS 13%9.0CVE-2006-0272Oracle10g vulnerabilityUnspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as …EPSS 5.8%9.0CVE-2004-1371Oracle application server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…EPSS 11%9.0CVE-2003-0222Oracle database server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via…EPSS 11%9.0CVE-2003-0096Oracle database server memory buffer overflow vulnerabilityMultiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2002-0965), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.