Oracle
oracle
10,864 CVEs • 1,061 products
Products (1,061)
Click to collapseToggle
Products (1,061)
Click to collapse
CVEs (10,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Oracle Vmware2Communications Cloud Native Core Policy Spring SecurityJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in...Show more |
3Fedoraproject OraclePython5Enterprise Manager Ops Center FedoraInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of...Show more |
2Oracle Prismjs2Application Express PrismJun 17, 2026 Jun 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a st...Show more |
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to...Show more |
Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise OpenGrok. Succes...Show more |
4Debian EclipseNetapp+1 more16Active Iq Unified Manager Autovue For Agile Product Lifecycle ManagementCommunications Element Manager+13 moreJun 17, 2026 Jun 22, 2021 N/A· v4 3.5 LOW· v3 3.6 LOW· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments w...Show more |
5Apache DebianFedoraproject+2 more6Communications Messaging Server Debian LinuxFedora+3 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. |
2Apache Oracle5Business Intelligence Communications Element ManagerCommunications Messaging Server+2 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restri...Show more |
3Apache FedoraprojectOracle7Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+4 moreJun 17, 2026 Jun 12, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. |
3Apache FedoraprojectOracle12Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+9 moreJun 17, 2026 Jun 12, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions. |
2Canonical Oracle2Openjdk Ubuntu LinuxJun 17, 2026 Jun 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users. |
5Haxx NetappOracle+2 more26Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 Jun 11, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortu...Show more |
6Debian FedoraprojectHaxx+3 more12Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+9 moreJun 17, 2026 Jun 11, 2021 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in th...Show more |
5Haxx NetappOracle+2 more22Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Function Cloud Native Environment+19 moreJun 17, 2026 Jun 11, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set wa...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF' |
5Apache DebianFedoraproject+2 more8Cloud Backup Debian LinuxEnterprise Manager Ops Center+5 moreJun 17, 2026 Jun 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could cre...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of...Show more |