Oracle
oracle
10,864 CVEs • 1,061 products
Products (1,061)
Click to collapseToggle
Products (1,061)
Click to collapse
CVEs (10,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache OracleQos26Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+23 moreJun 17, 2026 Jan 18, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. |
5Apache BroadcomNetapp+2 more28Advanced Supply Chain Planning Brocade SannavBusiness Intelligence+25 moreJun 17, 2026 Jan 18, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be includ...Show more |
5Apache BroadcomNetapp+2 more26Advanced Supply Chain Planning Brocade SannavBusiness Intelligence+23 moreJun 17, 2026 Jan 18, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has ac...Show more |
3Debian GnuOracle8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreJun 17, 2026 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer o...Show more |
3Debian GnuOracle4Communications Cloud Native Core Unified Data Repository Debian LinuxEnterprise Operations Monitor+1 moreJun 17, 2026 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer ov...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite Matrix ProjectJun 17, 2026 Jan 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite MailerJun 17, 2026 Jan 12, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname. |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite MailerJun 17, 2026 Jan 12, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname. |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsJun 17, 2026 Jan 12, 2022 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set. |
3Debian H2databaseOracle3Communications Cloud Native Core Policy Debian LinuxH2Jun 17, 2026 Jan 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI serve...Show more |
2Google Oracle7Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+4 moreJun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by...Show more |
2Oracle Vmware3Communications Cloud Native Core Console Communications Cloud Native Core Service Communication ProxySpring FrameworkJun 17, 2026 Jan 10, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to C...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraGdal+1 moreJun 17, 2026 Jan 1, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment). |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
3Fedoraproject OracleWireshark4Fedora Http ServerWireshark+1 moreJun 17, 2026 Dec 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file |
3Fedoraproject OracleWireshark4Fedora Http ServerWireshark+1 moreJun 17, 2026 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Dec 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file |
5Apache CiscoDebian+2 more22Cloudcenter Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+19 moreJun 17, 2026 Dec 28, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so...Show more |
2Linux Oracle4Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+1 moreJun 17, 2026 Dec 25, 2021 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small. |