CVE-2003-1208

Exp

Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

Published: 2004-12-03 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2003-1208 is rated High Exploit Risk (93.4/100): CVSS Critical severity, with high exploitation likelihood (EPSS 13.19%, 96th percentile). Core evidence: 11 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +4.81% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2003-1208

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2003-1208

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 8.38% 13.19% +4.81%
2 2025-03-30 4.95% 8.38% +3.43%
3 2025-03-29 4.95%

Full EPSS history (7 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2003-1208

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2003-1208

NVD evaluator notes for CVE-2003-1208

Solution: This was fixed in Oracle 9i Database Release 2, version 9.2.0.3.

Affected software / configurations for CVE-2003-1208

Vendor Product Version Raw CPE
oracle oracle9i enterprise_9.0.1 cpe:2.3:a:oracle:oracle9i:enterprise_9.0.1:*:*:*:*:*:*:*
oracle oracle9i enterprise_9.2.0 cpe:2.3:a:oracle:oracle9i:enterprise_9.2.0:*:*:*:*:*:*:*
oracle oracle9i enterprise_9.2.0.1 cpe:2.3:a:oracle:oracle9i:enterprise_9.2.0.1:*:*:*:*:*:*:*
oracle oracle9i enterprise_9.2.0.2 cpe:2.3:a:oracle:oracle9i:enterprise_9.2.0.2:*:*:*:*:*:*:*
oracle oracle9i personal_9.0.1 cpe:2.3:a:oracle:oracle9i:personal_9.0.1:*:*:*:*:*:*:*
oracle oracle9i personal_9.2 cpe:2.3:a:oracle:oracle9i:personal_9.2:*:*:*:*:*:*:*
oracle oracle9i personal_9.2.0.1 cpe:2.3:a:oracle:oracle9i:personal_9.2.0.1:*:*:*:*:*:*:*
oracle oracle9i personal_9.2.0.2 cpe:2.3:a:oracle:oracle9i:personal_9.2.0.2:*:*:*:*:*:*:*
oracle oracle9i standard_9.0 cpe:2.3:a:oracle:oracle9i:standard_9.0:*:*:*:*:*:*:*
oracle oracle9i standard_9.0.1 cpe:2.3:a:oracle:oracle9i:standard_9.0.1:*:*:*:*:*:*:*
oracle oracle9i standard_9.0.1.2 cpe:2.3:a:oracle:oracle9i:standard_9.0.1.2:*:*:*:*:*:*:*
oracle oracle9i standard_9.0.1.3 cpe:2.3:a:oracle:oracle9i:standard_9.0.1.3:*:*:*:*:*:*:*
oracle oracle9i standard_9.0.1.4 cpe:2.3:a:oracle:oracle9i:standard_9.0.1.4:*:*:*:*:*:*:*
oracle oracle9i standard_9.0.2 cpe:2.3:a:oracle:oracle9i:standard_9.0.2:*:*:*:*:*:*:*
oracle oracle9i standard_9.2 cpe:2.3:a:oracle:oracle9i:standard_9.2:*:*:*:*:*:*:*
oracle oracle9i standard_9.2.0.1 cpe:2.3:a:oracle:oracle9i:standard_9.2.0.1:*:*:*:*:*:*:*
oracle oracle9i standard_9.2.0.2 cpe:2.3:a:oracle:oracle9i:standard_9.2.0.2:*:*:*:*:*:*:*

References for CVE-2003-1208

URL Tags
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html Exploit Vendor Advisory
http://secunia.com/advisories/10805 Exploit Patch
http://www.ciac.org/ciac/bulletins/o-093.shtml Patch Vendor Advisory
http://www.kb.cert.org/vuls/id/240174 Patch Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/399806 Patch Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/819126 Patch Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/846582 Patch Third Party Advisory US Government Resource
http://www.nextgenss.com/advisories/ora_from_tz.txt Exploit Patch
http://www.nextgenss.com/advisories/ora_numtodsinterval.txt Exploit Patch
http://www.nextgenss.com/advisories/ora_numtoyminterval.txt Exploit Patch
http://www.nextgenss.com/advisories/ora_time_zone.txt Exploit
http://www.osvdb.org/3837 Exploit Patch Vendor Advisory
http://www.osvdb.org/3838 Exploit Patch Vendor Advisory
http://www.osvdb.org/3839 Exploit Patch Vendor Advisory
http://www.osvdb.org/3840 Exploit Patch Vendor Advisory
http://www.securityfocus.com/bid/9587 Exploit Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/15060
cvelogic Threat Intelligence