Oracle
oracle
11,037 CVEs • 1,064 products
Products (1,064)
Click to collapseToggle
Products (1,064)
Click to collapse
CVEs (11,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle4Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core PolicyHive+1 moreJun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. |
2Oracle Pyyaml2Communications Cloud Native Core Network Function Cloud Native Environment PyyamlJun 17, 2026 Feb 9, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader...Show more |
2Apache Oracle3Activemq Communications Session Report ManagerCommunications Session Route ManagerJun 17, 2026 Feb 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0. |
5Debian NetappNetty+2 more13Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+10 moreJun 17, 2026 Feb 8, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerab...Show more |
3Cryptography.io FedoraprojectOracle3Communications Cloud Native Core Network Function Cloud Native Environment CryptographyFedoraJun 17, 2026 Feb 7, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class...Show more |
2Jetbrains Oracle4Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core PolicyCommunications Cloud Native Core Service Communication Proxy+1 moreJun 17, 2026 Feb 3, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions. |
2Oracle Windriver2Communications Eagle VxworksJun 17, 2026 Feb 3, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by th...Show more |
2Gnupg Oracle2Communications Billing And Revenue Management LibgcryptJun 17, 2026 Jan 29, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later. |
5Debian FujitsuGnu+2 more11Communications Cloud Native Core Security Edge Protection Proxy Debian LinuxE Series Santricity Os Controller+8 moreJun 17, 2026 Jan 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentiall...Show more |
4Apache DebianNetapp+1 more9Activemq Activemq ArtemisArtemis+6 moreJun 17, 2026 Jan 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.1...Show more |
8Beyondtrust DebianFedoraproject+5 more24Active Iq Unified Manager Cloud BackupCommunications Performance Intelligence Center+21 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash...Show more |
2Ckeditor Oracle10Agile Plm Application ExpressBanking Party Management+7 moreJun 17, 2026 Jan 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin). |
2Ckeditor Oracle7Agile Plm Application ExpressCkeditor+4 moreJun 17, 2026 Jan 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin). |
2Apache Oracle3Financial Services Crime And Compliance Management Studio HadoopSolrJun 17, 2026 Jan 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. |
2Oracle Report Project3Communications Cloud Native Core Network Slice Selection Function Communications Pricing Design CenterReportJun 17, 2026 Jan 25, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forge...Show more |
2Kubernetes Oracle4Communications Cloud Native Core Network Slice Selection Function Communications Cloud Native Core PolicyCommunications Cloud Native Core Service Communication Proxy+1 moreJun 17, 2026 Jan 21, 2021 N/A· v4 5.0 MEDIUM· v3 6.0 MEDIUM· v2 Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patc...Show more |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker wi...Show more |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker wi...Show more |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker wi...Show more |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows low privileged attacker wit...Show more |