Oracle
oracle
10,864 CVEs • 1,061 products
Products (1,061)
Click to collapseToggle
Products (1,061)
Click to collapse
CVEs (10,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Linux NetappOracle26Aff A400 Firmware All Flash Fabric Attached Storage 8300 FirmwareAll Flash Fabric Attached Storage 8700 Firmware+23 moreJun 17, 2026 Dec 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers...Show more |
7Apache AppleDebian+4 more14Cloud Backup Communications Element ManagerCommunications Operations Monitor+11 moreJun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might...Show more |
6Apache AppleDebian+3 more12Communications Element Manager Communications Operations MonitorCommunications Session Report Manager+9 moreJun 17, 2026 Dec 20, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be...Show more |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreJun 17, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |
3Debian LinuxfoundationOracle5Communications Policy Management Debian LinuxDojo+2 moreJun 17, 2026 Dec 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. |
2Numpy Oracle2Communications Cloud Native Core Policy NumpyJun 17, 2026 Dec 17, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reporte...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
5Debian FedoraprojectLxml+2 more11Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Dec 13, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedde...Show more |
5Debian NetappNetty+2 more18Banking Deposits And Lines Of Credit Servicing Banking Party ManagementBanking Platform+15 moreJun 17, 2026 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are...Show more |
4Mozilla NetappOracle+1 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Repository Function+7 moreJun 17, 2026 Dec 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CM...Show more |
5Debian F5Oracle+2 more6Debian Linux Http ServerModsecurity+3 moreJun 17, 2026 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a modera...Show more |
3Ckeditor DrupalOracle9Agile Product Lifecycle Management Application ExpressBanking Apis+6 moreJun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inje...Show more |
4Ckeditor DrupalFedoraproject+1 more10Agile Plm Application ExpressBanking Apis+7 moreJun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allow...Show more |
5Debian FedoraprojectLinux+2 more15Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+12 moreJun 17, 2026 Nov 17, 2021 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 15, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. |
2Oracle Pypa4Agile Plm Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Policy+1 moreJun 17, 2026 Nov 10, 2021 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vul...Show more |
3Fedoraproject GolangOracle3Fedora GoTimesten In Memory DatabaseJun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. |
2Gnu Oracle7Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+4 moreJun 17, 2026 Nov 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This...Show more |
4Debian LinuxOracle+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Nov 4, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. |