Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25
Published Jan 18, 2006
5.5
MEDIUMCVSS 2.0
EPSS 2.00%
Description
Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2022-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 2.00% (0.02005) | 80.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.00% (0.02005) | 78.19th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.08% (0.01082) | 76.33th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.35% (0.00352) | 72.78th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.35% (0.00352) | 71.13th | v3 (v2023.03.01) |
| Jun 13, 2023 | 0.35% (0.00352) | 67.90th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.25% (0.00248) | 60.87th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (11)
- http://secunia.com/advisories/18493 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18608 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1015499 vdb-entryx_refsource_SECTRACK
- http://www.kb.cert.org/vuls/id/545804 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html x_refsource_CONFIRM
- http://www.osvdb.org/22563 vdb-entryx_refsource_OSVDB
- http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html x_refsource_MISC
- http://www.securityfocus.com/bid/16287 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/0243 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/0323 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/18493 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/18608 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securitytracker.com/id?1015499 | vdb-entryx_refsource_SECTRACK | |
| http://www.kb.cert.org/vuls/id/545804 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html | x_refsource_CONFIRM | |
| http://www.osvdb.org/22563 | vdb-entryx_refsource_OSVDB | |
| http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html | x_refsource_MISC | |
| http://www.securityfocus.com/bid/16287 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/0243 | vdb-entryx_refsource_VUPENVendor Advisory | |
| http://www.vupen.com/english/advisories/2006/0323 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.