Unrated severityNVD Advisory· Published Jan 18, 2006· Updated Apr 16, 2026
CVE-2006-0272
CVE-2006-0272
Description
Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29. NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.
Affected products
4cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:oracle9i:standard_9.2.0.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- secunia.com/advisories/18493nvdVendor Advisory
- secunia.com/advisories/18608nvdVendor Advisory
- www.kb.cert.org/vuls/id/545804nvdThird Party AdvisoryUS Government Resource
- www.vupen.com/english/advisories/2006/0243nvdVendor Advisory
- www.vupen.com/english/advisories/2006/0323nvdVendor Advisory
- www.kb.cert.org/vuls/id/891644nvdUS Government Resource
- www.us-cert.gov/cas/techalerts/TA06-018A.htmlnvdUS Government Resource
- archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.htmlnvd
- securitytracker.com/idnvd
- www.argeniss.com/research/ARGENISS-ADV-010601.txtnvd
- www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdfnvd
- www.oracle.com/technetwork/topics/security/cpujan2006-082403.htmlnvd
- www.red-database-security.com/advisory/oracle_cpu_jan_2006.htmlnvd
- www.securityfocus.com/bid/16287nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24321nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24376nvd
News mentions
0No linked articles in our index yet.