Oracle
oracle
11,112 CVEs • 1,067 products
Products (1,067)
Click to collapseToggle
Products (1,067)
Click to collapse
CVEs (11,112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oracle 1Retail Store Inventory Management Jun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security). The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privi...Show more |
6Canonical FedoraprojectLibssh+3 more6Cloud Backup Enterprise LinuxFedora+3 moreJun 17, 2026 Apr 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and...Show more |
5Netapp OracleSiemens+2 more12Communications Messaging Server Communications Network Charging And ControlEnterprise Manager Ops Center+9 moreJun 17, 2026 Apr 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement. |
7Canonical DebianNetapp+4 more18Communications Element Manager Communications Messaging ServerCommunications Network Charging And Control+15 moreJun 17, 2026 Apr 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. |
4Debian FasterxmlNetapp+1 more18Active Iq Unified Manager Banking PlatformCommunications Contacts Server+15 moreJun 17, 2026 Apr 7, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). |
4Debian FasterxmlNetapp+1 more21Active Iq Unified Manager Agile PlmBanking Platform+18 moreJun 17, 2026 Apr 7, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). |
5Debian FedoraprojectNetapp+2 more13Communications Brm Elastic Charging Engine Communications Cloud Native Core Service Communication ProxyCommunications Design Studio+10 moreJun 17, 2026 Apr 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...Show more |
8Apache BroadcomCanonical+5 more14Brocade Fabric Operating System Communications Element ManagerCommunications Session Report Manager+11 moreJun 17, 2026 Apr 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more |
3Apache NetappOracle10Communications Diameter Signaling Router Communications Diameter Signaling Router Idih\Communications Element Manager+7 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disa...Show more |
6Apache CanonicalDebian+3 more11Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+8 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. |
2Apple Oracle8Icloud IpadosIphone Os+5 moreJun 17, 2026 Apr 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iClou...Show more |
4Debian FasterxmlNetapp+1 more32Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+29 moreJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). |
4Debian FasterxmlNetapp+1 more31Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 moreJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). |
4Debian FasterxmlNetapp+1 more25Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+22 moreJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms)...Show more |
2Apache Oracle2Graalvm NetbeansJun 17, 2026 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected b...Show more |
2Apache Oracle2Graalvm NetbeansJun 17, 2026 Mar 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injec...Show more |
4Debian FasterxmlNetapp+1 more31Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 moreJun 17, 2026 Mar 26, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. |
4Debian FasterxmlNetapp+1 more31Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 moreJun 17, 2026 Mar 26, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). |
4Fedoraproject OpensuseOracle+1 more4Communications Cloud Native Core Network Function Cloud Native Environment FedoraLeap+1 moreJun 17, 2026 Mar 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoade...Show more |
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. |