Oracle
oracle
11,112 CVEs • 1,067 products
Products (1,067)
Click to collapseToggle
Products (1,067)
Click to collapse
CVEs (11,112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. |
4Debian FasterxmlNetapp+1 more31Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 moreJun 17, 2026 Mar 18, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). |
4Debian FasterxmlNetapp+1 more31Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 moreJun 17, 2026 Mar 18, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jm...Show more |
2Apache Oracle3Commons Configuration Database ServerHealthcare FoundationJun 17, 2026 Mar 13, 2020 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2....Show more |
9Canonical DebianFedoraproject+6 more11Banking Extensibility Workbench ChromeDebian Linux+8 moreJun 17, 2026 Mar 12, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unist...Show more |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraSolaris+3 moreJun 17, 2026 Mar 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the re...Show more |
3Debian LinuxfoundationOracle10Communications Application Session Controller Communications Policy ManagementCommunications Pricing Design Center+7 moreJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes,...Show more |
4Ckeditor DrupalFedoraproject+1 more11Agile Plm Application ExpressBanking Enterprise Default Management+8 moreJun 17, 2026 Mar 7, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected synt...Show more |
6Arista DebianFedoraproject+3 more6Communications Performance Intelligence Center Debian LinuxEos+3 moreJun 17, 2026 Mar 6, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. |
3Fasterxml NetappOracle4Goldengate Stream Analytics Jackson DatabindOncommand Api Services+1 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction wi...Show more |
4Debian FasterxmlNetapp+1 more25Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+22 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). |
4Debian FasterxmlNetapp+1 more16Active Iq Unified Manager Autovue For Agile Product Lifecycle ManagementBanking Platform+13 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). |
4Debian FasterxmlNetapp+1 more31Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+28 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). |
7Apache BlackberryDebian+4 more21Agile Engineering Data Management Agile PlmCommunications Element Manager+18 moreJun 17, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Apache DebianNetapp+2 more16Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+13 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |
2Dropwizard Oracle2Blockchain Platform Dropwizard ValidationJun 17, 2026 Feb 24, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions whe...Show more |
5Canonical NetappOracle+2 more11Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+8 moreJun 17, 2026 Feb 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations. |
5Debian FasterxmlHuawei+2 more8Debian Linux Global Lifecycle Management OpatchJackson Databind+5 moreJun 17, 2026 Feb 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. |
5Debian OpensuseOracle+2 more5Communications Diameter Signaling Router Debian LinuxLeap+2 moreJun 17, 2026 Feb 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big...Show more |