Oracle
oracle
11,037 CVEs • 1,064 products
Products (1,064)
Click to collapseToggle
Products (1,064)
Click to collapse
CVEs (11,037)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject MozillaOracle+1 more6Communications Offline Mediation Controller Communications Pricing Design CenterEnterprise Linux+3 moreJun 17, 2026 Oct 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library....Show more |
4Apache DebianJunit+1 more4Communications Cloud Native Core Policy Debian LinuxJunit4+1 moreJun 17, 2026 Oct 12, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on tha...Show more |
3Apache DebianOracle4Debian Linux Instantis EnterprisetrackSd Wan Edge+1 moreJun 17, 2026 Oct 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol...Show more |
4Cure53 DebianMicrosoft+1 more5Application Express Debian LinuxDompurify+2 moreJun 17, 2026 Oct 7, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by ne...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraWireshark+1 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement. |
4Fedoraproject OpensuseOracle+1 more4Fedora LeapWireshark+1 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/pac...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts. |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum. |
8Canonical DebianFedoraproject+5 more8Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to b...Show more |
4Apache FedoraprojectGradle+1 more37Agile Engineering Data Management AntApi Gateway+34 moreJun 17, 2026 Oct 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file...Show more |
4Canonical DebianOracle+1 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxUbuntu Linux+2 moreJun 17, 2026 Sep 30, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-...Show more |
7Canonical DebianFedoraproject+4 more8Debian Linux FedoraHci Storage Node+5 moreJun 17, 2026 Sep 27, 2020 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF cont...Show more |
3Netapp OracleVmware38Commerce Guided Search Communications BrmCommunications Design Studio+35 moreJun 17, 2026 Sep 19, 2020 N/A· v4 6.5 MEDIUM· v3 3.6 LOW· v2 In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser...Show more |
3Debian FasterxmlOracle26Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+23 moreJun 17, 2026 Sep 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. |
2Google Oracle4Android Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+1 moreJun 17, 2026 Sep 17, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges n...Show more |
2Oracle Ua Parser Js Project2Communications Cloud Native Core Network Function Cloud Native Environment Ua Parser JsJun 17, 2026 Sep 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA. |
2Apache Oracle5Communications Policy Management Financial Services Data Integration HubFinancial Services Market Risk Measurement And Management+2 moreJun 17, 2026 Sep 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload. |
2Apache Oracle5Communications Policy Management Financial Services Data Integration HubFinancial Services Market Risk Measurement And Management+2 moreJun 17, 2026 Sep 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. |
3Apache DebianOracle4Activemq Communications Diameter Signaling RouterDebian Linux+1 moreJun 17, 2026 Sep 10, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method...Show more |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 Sep 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open t...Show more |