Reportedly Oracle Database 9i is affected by an SQL command buffer overflow vulnerability.

This story continues at http://www.databasejournal.com/news/article.php/3409911