CVEs (143)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Eclipse NetappOracle25Autovue Communications AnalyticsCommunications Element Manager+22 moreJun 17, 2026 Apr 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for sho...Show more |
4Apache DebianNetapp+1 more8Activemq Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Mar 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive. |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
1Oracle 1Enterprise Manager Base Platform Nov 21, 2024 Jan 16, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: EM Console). Supported versions that are affected are 13.2 and 13.3. Easily exploitable vulnerabi...Show more |
7Canonical DebianNodejs+4 more20Api Gateway Application ServerDebian Linux+17 moreJun 17, 2026 Nov 15, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. |
6Canonical DebianNetapp+3 more19Api Gateway Cloud BackupCn1610 Firmware+16 moreNov 21, 2024 Oct 30, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
3Apache NetappOracle8Active Iq Unified Manager Communications Policy ManagementEnterprise Manager Base Platform+5 moreOct 27, 2025 Aug 22, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with...Show more |
3Ibm OracleRedhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreNov 21, 2024 Aug 20, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files....Show more |
2Eclipse Oracle2Enterprise Manager Base Platform Openj9Nov 21, 2024 Aug 14, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the abilit...Show more |
3Apache DebianOracle38Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+35 moreJun 17, 2026 Aug 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. |
4Bouncycastle NetappOpensuse+1 more24Api Gateway Banking PlatformBc Java+21 moreMay 12, 2025 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vuln...Show more |
3Debian OracleVmware34Agile Plm Agile Product Lifecycle ManagementApplication Testing Suite+31 moreAug 25, 2026 Jun 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the Hid...Show more |
3Oracle RedhatVmware30Agile Product Lifecycle Management Application Testing SuiteBig Data Discovery+27 moreNov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through t...Show more |
1Oracle 1Enterprise Manager Base Platform Nov 21, 2024 Apr 19, 2018 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: UI Framework). The supported version that is affected is 12.1.0.5. Easily exploitable vulnerabili...Show more |
1Oracle 1Enterprise Manager Base Platform May 13, 2026 Aug 8, 2017 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily exploitab...Show more |
3Debian EclipseOracle7Communications Cloud Native Core Policy Debian LinuxEnterprise Manager Base Platform+4 moreMay 13, 2026 Jun 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords. |
1Oracle 1Enterprise Manager Base Platform May 13, 2026 Apr 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily "e...Show more |
4Apache NetappOracle+1 more79Api Gateway Application Testing SuiteAutovue Vuelink Integration+76 moreMay 13, 2026 Apr 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, c...Show more |
1Oracle 1Enterprise Manager Base Platform May 6, 2026 Oct 25, 2016 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Fr...Show more |