Oracle
oracle
11,112 CVEs • 1,067 products
Products (1,067)
Click to collapseToggle
Products (1,067)
Click to collapse
CVEs (11,112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OracleUclouvain3Debian Linux OpenjpegOutside In TechnologyJun 17, 2026 Jun 29, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be...Show more |
5Apple CanonicalOracle+2 more16Communications Cloud Native Core Policy Communications Messaging ServerCommunications Network Charging And Control+13 moreJun 17, 2026 Jun 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. |
6Apache CanonicalDebian+3 more8Debian Linux LeapMysql Enterprise Monitor+5 moreJun 17, 2026 Jun 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such reques...Show more |
2Net Snmp Oracle2Net Snmp Zfs Storage Appliance KitJun 17, 2026 Jun 25, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, bu...Show more |
4Netapp NtpOpensuse+1 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used...Show more |
2Apache Oracle2Business Intelligence SparkJun 17, 2026 Jun 23, 2020 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master...Show more |
4Fedoraproject OpensuseOracle+1 more4Enterprise Manager Ops Center FedoraLeap+1 moreJun 17, 2026 Jun 18, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more |
4Debian FasterxmlNetapp+1 more14Active Iq Unified Manager Agile PlmBanking Digital Experience+11 moreJun 17, 2026 Jun 16, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). |
4Debian OracleRedislabs+1 more4Communications Operations Monitor Debian LinuxLinux Enterprise+1 moreJun 17, 2026 Jun 15, 2020 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and a...Show more |
6Apple GitlabNetapp+3 more15Active Iq Unified Manager Cloud BackupClustered Data Ontap+12 moreJun 17, 2026 Jun 15, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. |
3Fasterxml NetappOracle12Active Iq Unified Manager Agile PlmBanking Digital Experience+9 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). |
4Debian FasterxmlNetapp+1 more13Active Iq Unified Manager Agile PlmBanking Digital Experience+10 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). |
4Debian FasterxmlNetapp+1 more15Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+12 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms....Show more |
2Nodejs Oracle5Banking Extensibility Workbench Blockchain PlatformGraalvm+2 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. |
6Debian FedoraprojectNetapp+3 more12Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+9 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. |
5Fedoraproject NetappOpensuse+2 more16Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+13 moreJun 17, 2026 Jun 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. |
5Fedoraproject NetappOpensuse+2 more17Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+14 moreJun 17, 2026 Jun 5, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. |
4Fedoraproject OpensuseOracle+1 more15Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+12 moreJun 17, 2026 Jun 5, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. |
6Debian FedoraprojectNghttp2+3 more10Banking Extensibility Workbench Blockchain PlatformDebian Linux+7 moreJun 17, 2026 Jun 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 byt...Show more |
2Cisco Oracle3Goldengate Management Pack IosIos XeJun 17, 2026 Jun 3, 2020 N/A· v4 7.7 HIGH· v3 6.3 MEDIUM· v2 A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial...Show more |