Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15060
http://www.kb.cert.org/vuls/id/846582
http://www.kb.cert.org/vuls/id/819126
http://www.kb.cert.org/vuls/id/399806