# CVE-2003-0894

## Summary

- **CVE ID:** CVE-2003-0894
- **Severity:** UNKNOWN
- **CVSS Score:** 0.01
- **CWE:** N/A
- **Published:** Oct 25, 2003
- **Last Modified:** Mar 16, 2026

## Description

Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.securityfocus.com/bid/8844)
- [CNA](http://www.securityfocus.com/bid/8845)
- [CNA](http://www.kb.cert.org/vuls/id/496340)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/13451)
- [CNA](http://otn.oracle.com/deploy/security/pdf/2003alert59.pdf)
- [CNA](http://securitytracker.com/id?1007956)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 44.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._