Description
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.
Remediation
References
Related Vulnerabilities
WordPress 4.4.x Cross-Domain Flash Injection Vulnerability (4.4 - 4.4.13)
MySQL CVE-2018-3056 Vulnerability (CVE-2018-3056)
Joomla! Core 3.x.x Information Disclosure (3.0.0 - 3.8.7)
PostgreSQL Untrusted Search Path Vulnerability (CVE-2020-10733)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2009-2372)