CVE-2004-1774

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
31 August 2004

Summary

Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.

References

EPSS Score

97% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.