← Vulnerability feed

Vulnerability record · CVE-2003-1208 · published 3 December 2004

CVE-2003-1208: Oracle9i vulnerability

Oracle · Oracle9i

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

10.0 CVSS 2.0 High EPSS 13% · top 3.8%
10.0CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References, 22 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html ExploitVendor Advisory
http://secunia.com/advisories/10805 ExploitPatch
http://www.ciac.org/ciac/bulletins/o-093.shtml PatchVendor Advisory
http://www.kb.cert.org/vuls/id/240174 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/399806 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/819126 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/846582 PatchThird Party AdvisoryUS Government Resource
http://www.nextgenss.com/advisories/ora_from_tz.txt ExploitPatch
http://www.nextgenss.com/advisories/ora_numtodsinterval.txt ExploitPatch
http://www.nextgenss.com/advisories/ora_numtoyminterval.txt ExploitPatch
http://www.nextgenss.com/advisories/ora_time_zone.txt Exploit
http://www.osvdb.org/3837 ExploitPatchVendor Advisory
http://www.osvdb.org/3838 ExploitPatchVendor Advisory
http://www.osvdb.org/3839 ExploitPatchVendor Advisory
http://www.osvdb.org/3840 ExploitPatchVendor Advisory
http://www.securityfocus.com/bid/9587 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15060
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html ExploitVendor Advisory
http://secunia.com/advisories/10805 ExploitPatch
http://www.ciac.org/ciac/bulletins/o-093.shtml PatchVendor Advisory
http://www.kb.cert.org/vuls/id/240174 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/399806 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/819126 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/846582 PatchThird Party AdvisoryUS Government Resource
http://www.nextgenss.com/advisories/ora_from_tz.txt ExploitPatch
http://www.nextgenss.com/advisories/ora_numtodsinterval.txt ExploitPatch
http://www.nextgenss.com/advisories/ora_numtoyminterval.txt ExploitPatch
http://www.nextgenss.com/advisories/ora_time_zone.txt Exploit
http://www.osvdb.org/3837 ExploitPatchVendor Advisory
http://www.osvdb.org/3838 ExploitPatchVendor Advisory
http://www.osvdb.org/3839 ExploitPatchVendor Advisory
http://www.osvdb.org/3840 ExploitPatchVendor Advisory
http://www.securityfocus.com/bid/9587 ExploitPatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15060

Track CVE-2003-1208 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-0262Oracle database server vulnerabilityUnspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has u…EPSS 3.9%10.0CVE-2006-0271Oracle database server vulnerabilityUnspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impa…EPSS 3.4%10.0CVE-2003-0095Oracle database server memory buffer overflow vulnerabilityBuffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long userna…EPSS 13%9.0CVE-2006-0272Oracle10g vulnerabilityUnspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as …EPSS 5.8%9.0CVE-2004-1371Oracle application server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…EPSS 11%9.0CVE-2003-0222Oracle database server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via…EPSS 11%9.0CVE-2003-0096Oracle database server memory buffer overflow vulnerabilityMultiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a…EPSS 16%8.5CVE-2004-0638Oracle8i memory buffer overflow vulnerabilityBuffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, …EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2003-1208), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.