« Back to list

CVE-2007-1442

Status: ModifiedHigh (7.2)—

Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2007-1442",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-03-14T00:19:00.000",
  "references": [
    {
      "url": "http://argeniss.com/research/10MinSecAudit.zip",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/33979",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24475",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/22905",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://argeniss.com/research/10MinSecAudit.zip",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/33979",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24475",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/22905",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges."
    },
    {
      "lang": "es",
      "value": "Oracle Database 10g utiliza un parámetro pDacl nulo al llamar a la función que crea listas de control de acceso discrecionales (DACLs), lo cual permite a usuarios locales obtener privilegios."
    }
  ],
  "lastModified": "2026-06-16T22:37:35.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.1:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E3D77A8-E553-4634-8CA6-C68224454930"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.1:*:personal:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE3C363B-E95D-470E-8BD7-90A959BC89E4"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.1:*:standard:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E60EFC05-0B57-4848-AFA3-951A72FDD8DC"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.2:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E3D7502-C7EC-4AAF-80BF-ACB99235093D"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.2:*:personal:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABC86628-BFBE-4DBB-9283-9C3A1E4E3282"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.2:*:standard:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08785B18-AE2E-420B-BCEC-6159D4B67C01"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.3:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "765563B1-3E03-44C0-B6AD-581CF70E3048"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.3:*:personal:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00D24B8A-FF43-4298-82AD-46CA8EBC9CA4"
            },
            {
              "criteria": "cpe:2.3:a:oracle:database_server:10.2.3:*:standard:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "032555AE-EAA5-46EA-ACAF-9FBB4F42D95F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}