CVE-2002-0965
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 70%
from disclosure to weapon2793 days
Published on NVDApr 2
1st PoC+2793d
metasploitMay 27
exploitation probability
70%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16341unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0096.htmlhttp://online.securityfocus.com/archive/1/276526http://otn.oracle.com/deploy/security/pdf/net9_dos_alert.pdfhttp://www.iss.net/security_center/static/9288.phphttp://www.kb.cert.org/vuls/id/630091http://www.securityfocus.com/bid/4845