Oracle
oracle
10,864 CVEs • 1,061 products
Products (1,061)
Click to collapseToggle
Products (1,061)
Click to collapse
CVEs (10,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectOracle5Enterprise Manager Ops Center FedoraHttp Server+2 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent reques...Show more |
4Debian EclipseNetapp+1 more8Active Iq Unified Manager Communications Cloud Native Core PolicyDebian Linux+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to...Show more |
4Debian FedoraprojectGnupg+1 more8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for...Show more |
3Debian OracleWireshark5Debian Linux Enterprise Manager Ops CenterInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file |
2Oracle Websockets Project5Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection ProxyCommunications Cloud Native Core Service Communication Proxy+2 moreJun 17, 2026 Jun 6, 2021 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able...Show more |
2Gulpjs Oracle2Communications Cloud Native Core Policy Glob ParentJun 17, 2026 Jun 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator. |
2Eclipse Oracle9Banking Enterprise Default Management Banking PlatformCommunications Network Integrity+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. |
4Gstreamer Gstreamer ProjectNetapp+1 more13Active Iq Unified Manager E Series Santricity Os ControllerE Series Santricity Storage Manager+10 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. |
4Lz4 Project NetappOracle+1 more7Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Policy+4 moreJun 17, 2026 Jun 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-b...Show more |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreJun 17, 2026 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |
2Json Smart Project Oracle3Json Smart V1 Json Smart V2Utilities FrameworkJun 17, 2026 Jun 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request. |
6Debian FedoraprojectNetapp+3 more9Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorDebian Linux+6 moreJun 17, 2026 Jun 1, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidenti...Show more |
5F5 FedoraprojectNetapp+2 more13Blockchain Platform Communications Control Plane MonitorCommunications Fraud Monitor+10 moreJun 17, 2026 Jun 1, 2021 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other...Show more |
5Debian FedoraprojectNetapp+2 more17Banking Cash Management Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+14 moreJun 17, 2026 May 28, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipu...Show more |
3Netapp OracleVmware32Commerce Guided Search Communications Brm Elastic Charging EngineCommunications Cloud Native Core Binding Support Function+29 moreJun 17, 2026 May 27, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticat...Show more |
3Eclipse OracleQuarkus4Communications Cloud Native Core Policy Jakarta Expression LanguageQuarkus+1 moreJun 17, 2026 May 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. |
2Oracle Redhat8Ansible Ansible TowerCisco Nx Os Collection+5 moreJun 17, 2026 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to...Show more |
6Debian FedoraprojectNetapp+3 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionDebian Linux+7 moreJun 17, 2026 May 20, 2021 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive inform...Show more |
3Fedoraproject OpenidcOracle3Essbase FedoraMod Auth OpenidcJun 17, 2026 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. |
6Debian FedoraprojectNetapp+3 more28Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+25 moreJun 17, 2026 May 19, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of...Show more |