← Vulnerability feed

Vulnerability record · CVE-2002-1264 · published 12 November 2002

CVE-2002-1264: Oracle9i vulnerability

Oracle · Oracle9i

Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.

7.5 CVSS 2.0 High EPSS 7.7% · top 5.6%
7.5CVSS 2.0 base score
7.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1264 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-0262Oracle database server vulnerabilityUnspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has u…EPSS 3.9%10.0CVE-2006-0271Oracle database server vulnerabilityUnspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impa…EPSS 3.4%10.0CVE-2003-1208Oracle9i vulnerabilityMultiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to…EPSS 13%10.0CVE-2003-0095Oracle database server memory buffer overflow vulnerabilityBuffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long userna…EPSS 13%9.0CVE-2006-0272Oracle10g vulnerabilityUnspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as …EPSS 5.8%9.0CVE-2004-1371Oracle application server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…EPSS 11%9.0CVE-2003-0222Oracle database server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via…EPSS 11%9.0CVE-2003-0096Oracle database server memory buffer overflow vulnerabilityMultiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2002-1264), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.