CVE-2009-0991

Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7 - Denial of Service in Listener Component

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0991. PoCs published by Dennis Yurichev.

AI-analyzed exploit summary This exploit targets a vulnerability in Oracle RDBMS TNS Listener (CVE-2009-0991) by sending malformed packets to cause a trap in the Listener process. It specifically exploits a flaw in the memcpy() function within ncrfintn() in oranro11.dll.

Description

Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-1970.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dennis Yurichev · pythondoswindows
https://www.exploit-db.com/exploits/8507

This exploit targets a vulnerability in Oracle RDBMS TNS Listener (CVE-2009-0991) by sending malformed packets to cause a trap in the Listener process. It specifically exploits a flaw in the memcpy() function within ncrfintn() in oranro11.dll.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Oracle RDBMS Win32 11.1.0.6.0 and 10.2.0.3
No auth needed
Prerequisites: Network access to the target Oracle TNS Listener on port 1521
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34461
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34693
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-105A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/53737
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022052
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50026

Scores

EPSS 0.0758
EPSS Percentile 93.8%

Details

Status published
Products (5)
oracle/database_10g 10.1.0.5
oracle/database_10g 10.2.0.4
oracle/database_11g 11.1.0.7
oracle/database_9i 9.2.0.8
oracle/database_9i 9.2.0.8dv
Published Apr 15, 2009
Tracked Since Feb 18, 2026