← Vulnerability feed

Vulnerability record · CVE-2004-0638 · published 31 December 2004

CVE-2004-0638: Oracle8i memory buffer overflow vulnerability

Oracle · Oracle8i

Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.

8.5 CVSS 2.0 High EPSS 6.6% · top 6.4% CWE-119 · Memory buffer overflow
8.5CVSS 2.0 base score
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.

AV:N/AC:M/Au:S/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-0262Oracle database server vulnerabilityUnspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has u…EPSS 3.9%10.0CVE-2006-0271Oracle database server vulnerabilityUnspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impa…EPSS 3.4%10.0CVE-2003-1208Oracle9i vulnerabilityMultiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to…EPSS 13%10.0CVE-2003-0095Oracle database server memory buffer overflow vulnerabilityBuffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long userna…EPSS 13%10.0CVE-2001-0499Oracle 8i TNS Listener buffer overflow via command argumentsThe Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier contains a buffer overflow reachable through long arguments to the ST…EPSS 85%analysed9.0CVE-2006-0272Oracle10g vulnerabilityUnspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as …EPSS 5.8%9.0CVE-2004-1371Oracle application server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedur…EPSS 11%9.0CVE-2003-0222Oracle database server memory buffer overflow vulnerabilityStack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2004-0638), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.