Vulnerability record · CVE-2003-0727 · published 20 October 2003
CVE-2003-0727: Oracle 9i XML Database local buffer overflows
Oracle · Database Server
Oracle 9i Database Release 2 contains multiple buffer overflows in its XML Database (XDB) functionality. The flaws are reachable by local users and can crash the database or let an attacker hijack user sessions. The record gives no affected version detail beyond Release 2 and no root-cause specifics.
Description
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.
AV:L/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityLocal-only access and low CVSS 2.1 limit reach, but high EPSS and public exploit code raise the practical risk for exposed database hosts.
What it is
Oracle 9i Database Release 2 contains multiple buffer overflows in its XML Database (XDB) functionality. The flaws are reachable by local users and can crash the database or let an attacker hijack user sessions. The record gives no affected version detail beyond Release 2 and no root-cause specifics.
Impact
An attacker with local access can cause a denial of service against the database or take over another user's session. Session hijacking could expose data and actions available to the compromised session.
Attack surface
The vector is AV:L, so the flaw is reached locally on the host, not over the network. No authentication is required per the vector (Au:N), and no user interaction is indicated.
Exploitation
CVE-2003-0727 is not listed in CISA KEV, but EPSS is high at 0.684 (99.3rd percentile) and public Exploit-DB code exists, so exploitation is plausible. No ransomware use is documented.
What to do
- Apply the Oracle security alert fix referenced in the vendor advisory (2003Alert58) or upgrade to a supported Oracle release.
- Restrict local login and OS-level access to database hosts to trusted accounts only.
- Limit which accounts can use XDB functionality and disable XDB if it is not required.
- Monitor and audit local sessions for abnormal termination or session takeover patterns.
Detection
- Alert on unexpected database instance crashes or restarts on Oracle 9i hosts.
- Review OS and database audit logs for local users invoking XDB components.
- Correlate local logins with session identity changes or concurrent session anomalies.
- Watch for known Exploit-DB 42780 activity or related local exploit binaries on database servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0727 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.