CVE-2003-1208
Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.
Date published : 2005-05-19
http://www.securityfocus.com/bid/9587
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0030.html