← Vulnerability feed

Vulnerability record · CVE-2003-0727 · published 20 October 2003

CVE-2003-0727: Oracle 9i XML Database local buffer overflows

Oracle · Database Server

Oracle 9i Database Release 2 contains multiple buffer overflows in its XML Database (XDB) functionality. The flaws are reachable by local users and can crash the database or let an attacker hijack user sessions. The record gives no affected version detail beyond Release 2 and no root-cause specifics.

2.1 CVSS 2.0 Low EPSS 68% · top 0.7%
2.1CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.

AV:L/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityLocal-only access and low CVSS 2.1 limit reach, but high EPSS and public exploit code raise the practical risk for exposed database hosts.

What it is

Oracle 9i Database Release 2 contains multiple buffer overflows in its XML Database (XDB) functionality. The flaws are reachable by local users and can crash the database or let an attacker hijack user sessions. The record gives no affected version detail beyond Release 2 and no root-cause specifics.

Impact

An attacker with local access can cause a denial of service against the database or take over another user's session. Session hijacking could expose data and actions available to the compromised session.

Attack surface

The vector is AV:L, so the flaw is reached locally on the host, not over the network. No authentication is required per the vector (Au:N), and no user interaction is indicated.

Exploitation

CVE-2003-0727 is not listed in CISA KEV, but EPSS is high at 0.684 (99.3rd percentile) and public Exploit-DB code exists, so exploitation is plausible. No ransomware use is documented.

What to do

  • Apply the Oracle security alert fix referenced in the vendor advisory (2003Alert58) or upgrade to a supported Oracle release.
  • Restrict local login and OS-level access to database hosts to trusted accounts only.
  • Limit which accounts can use XDB functionality and disable XDB if it is not required.
  • Monitor and audit local sessions for abnormal termination or session takeover patterns.

Detection

  • Alert on unexpected database instance crashes or restarts on Oracle 9i hosts.
  • Review OS and database audit logs for local users invoking XDB components.
  • Correlate local logins with session identity changes or concurrent session anomalies.
  • Watch for known Exploit-DB 42780 activity or related local exploit binaries on database servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1953Apache commons configuration vulnerabilityApache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…EPSS 6.8%10.0CVE-2015-4863Oracle database server vulnerabilityUnspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to…EPSS 3.1%10.0CVE-2013-1534Oracle database server vulnerabilityUnspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows …EPSS 3.7%10.0CVE-2010-0071Oracle database server vulnerabilityUnspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers t…EPSS 9.8%10.0CVE-2009-1979Oracle Database Network Authentication component remote code execution riskAn unspecified flaw in the Network Authentication component of Oracle Database 10.1.0.5 and 10.2.0.4 lets remote attackers affect confidentiality, in…EPSS 76%analysed10.0CVE-2009-1985Oracle database server vulnerabilityUnspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attacke…EPSS 5.4%10.0CVE-2009-1992Oracle database server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidenti…EPSS 4.2%10.0CVE-2008-1818Oracle database server vulnerabilityUnspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2003-0727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.