← Back

Oracle

oracle

11,112 CVEs • 1,067 products

Products (1,067)

Click to collapse
Toggle
Mysql
mysql
Jre
jre
Jdk
jdk
Solaris
solaris
Mysql Server
mysql_server
Linux
linux
Graalvm
graalvm
Http Server
http_server
Jrockit
jrockit
Openjdk
openjdk
Siebel Crm
siebel_crm
Mysql Cluster
mysql_cluster
Agile Plm
agile_plm
Marketing
marketing
Database
database
Javafx
javafx
Oracle9i
oracle9i
Berkeley Db
berkeley_db
Coherence
coherence
Oracle8i
oracle8i
Istore
istore
Vm Server
vm_server

CVEs (11,112)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Retail Store Inventory Management
Jun 17, 2026
Apr 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security). The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privi...Show more
Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security). The supported version that is affected is 16.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Store Inventory Management. Successful attacks of this vulnerability can result in takeover of Oracle Retail Store Inventory Management. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).Show less
6Canonical
FedoraprojectLibssh+3 more
6Cloud Backup
Enterprise LinuxFedora+3 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and...Show more
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.Show less
5Netapp
OracleSiemens+2 more
12Communications Messaging Server
Communications Network Charging And ControlEnterprise Manager Ops Center+9 more
Jun 17, 2026
Apr 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
7Canonical
DebianNetapp+4 more
18Communications Element Manager
Communications Messaging ServerCommunications Network Charging And Control+15 more
Jun 17, 2026
Apr 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
4Debian
FasterxmlNetapp+1 more
18Active Iq Unified Manager
Banking PlatformCommunications Contacts Server+15 more
Jun 17, 2026
Apr 7, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
4Debian
FasterxmlNetapp+1 more
21Active Iq Unified Manager
Agile PlmBanking Platform+18 more
Jun 17, 2026
Apr 7, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
5Debian
FedoraprojectNetapp+2 more
13Communications Brm Elastic Charging Engine
Communications Cloud Native Core Service Communication ProxyCommunications Design Studio+10 more
Jun 17, 2026
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...Show more
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.Show less
8Apache
BroadcomCanonical+5 more
14Brocade Fabric Operating System
Communications Element ManagerCommunications Session Report Manager+11 more
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.Show less
3Apache
NetappOracle
10Communications Diameter Signaling Router
Communications Diameter Signaling Router Idih\Communications Element Manager+7 more
Jun 17, 2026
Apr 1, 2020
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disa...Show more
Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.Show less
6Apache
CanonicalDebian+3 more
11Communications Element Manager
Communications Session Report ManagerCommunications Session Route Manager+8 more
Jun 17, 2026
Apr 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
2Apple
Oracle
8Icloud
IpadosIphone Os+5 more
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iClou...Show more
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.Show less
4Debian
FasterxmlNetapp+1 more
32Agile Plm
Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+29 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
4Debian
FasterxmlNetapp+1 more
31Agile Plm
Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
4Debian
FasterxmlNetapp+1 more
25Agile Plm
Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+22 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms)...Show more
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).Show less
2Apache
Oracle
2Graalvm
Netbeans
Jun 17, 2026
Mar 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected b...Show more
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.Show less
2Apache
Oracle
2Graalvm
Netbeans
Jun 17, 2026
Mar 30, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injec...Show more
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.Show less
4Debian
FasterxmlNetapp+1 more
31Agile Plm
Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 more
Jun 17, 2026
Mar 26, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
4Debian
FasterxmlNetapp+1 more
31Agile Plm
Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 more
Jun 17, 2026
Mar 26, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
4Fedoraproject
OpensuseOracle+1 more
4Communications Cloud Native Core Network Function Cloud Native Environment
FedoraLeap+1 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoade...Show more
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.Show less
4Apache
CanonicalDebian+1 more
6Business Process Management Suite
Communications Messaging ServerDebian Linux+3 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.