Show plain JSON{"id": "CVE-2008-1820", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2008-04-16T10:05:00.000", "references": [{"url": "http://secunia.com/advisories/29829", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/29874", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/491024/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/491024/100/0/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/archive/1/491524/30/390/threaded", "source": "cve@mitre.org"}, {"url": "http://www.securitytracker.com/id?1019855", "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2008/1233/references", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.vupen.com/english/advisories/2008/1267/references", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41858", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42036", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/29829", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/29874", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/491024/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/491024/100/0/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/archive/1/491524/30/390/threaded", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securitytracker.com/id?1019855", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2008/1233/references", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.vupen.com/english/advisories/2008/1267/references", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41858", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/42036", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "Unspecified vulnerability in the Data Pump component in Oracle Database 9.2.0.8, 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote attack vectors related to KUPF$FILE_INT, aka DB11. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that DB11 is for a buffer overflow in the SYS.KUPF$FILE_INT.GET_FULL_FILENAME procedure."}, {"lang": "es", "value": "Una vulnerabilidad no especificada en el componente Data Pump en Oracle Database versiones 9.2.0.8, 10.1.0.5, 10.2.0.3 y 11.1.0.6, presenta un impacto desconocido y vectores de ataque remotos relacionados con KUPF$FILE_INT, tambi\u00e9n se conoce como DB11. NOTA: la informaci\u00f3n anterior fue obtenida de la CPU de abril de 2008. Oracle no ha comentado sobre las afirmaciones de investigadores confiables que DB11 es para un desbordamiento de b\u00fafer en el procedimiento SYS. KUPF$FILE_INT. GET_FULL_FILENAME."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:oracle:database_10g:10.1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB9DC5FD-9892-47BD-8F35-A3D4556952A1"}, {"criteria": "cpe:2.3:a:oracle:database_10g:10.2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6D836B0-A20F-49D8-9EE3-251BA2D28247"}, {"criteria": "cpe:2.3:a:oracle:database_11g:11.1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D2E2826-26E2-4AFD-808B-04C9D8FA5FF4"}, {"criteria": "cpe:2.3:a:oracle:database_9i:9.2.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35853080-470C-415B-B15B-D93A6DE856FF"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}