← Back

Oracle

oracle

11,112 CVEs • 1,067 products

Products (1,067)

Click to collapse
Toggle
Mysql
mysql
Jre
jre
Jdk
jdk
Solaris
solaris
Mysql Server
mysql_server
Linux
linux
Graalvm
graalvm
Http Server
http_server
Jrockit
jrockit
Openjdk
openjdk
Siebel Crm
siebel_crm
Mysql Cluster
mysql_cluster
Agile Plm
agile_plm
Marketing
marketing
Database
database
Javafx
javafx
Oracle9i
oracle9i
Berkeley Db
berkeley_db
Coherence
coherence
Oracle8i
oracle8i
Istore
istore
Vm Server
vm_server

CVEs (11,112)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
8Debian
NetappOpensuse+5 more
11Backports Sle
Cloud BackupDebian Linux+8 more
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
5Fedoraproject
NpmjsOpensuse+2 more
6Enterprise Linux
Enterprise Linux EusFedora+3 more
Jun 17, 2026
Dec 13, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package...Show more
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.Show less
5Fedoraproject
NpmjsOpensuse+2 more
6Enterprise Linux
Enterprise Linux EusFedora+3 more
Jun 17, 2026
Dec 13, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in...Show more
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.Show less
5Fedoraproject
NpmjsOpensuse+2 more
6Enterprise Linux
Enterprise Linux EusFedora+3 more
Jun 17, 2026
Dec 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A prop...Show more
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.Show less
4Fedoraproject
OracleQuarkus+1 more
4Fedora
Peoplesoft Enterprise Pt PeopletoolsQuarkus+1 more
Nov 21, 2024
Dec 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on...Show more
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.Show less
8Canonical
DebianFedoraproject+5 more
15Backports Sle
ChromeCommunications Cloud Native Core Network Repository Function+12 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
5Netapp
OracleSiemens+2 more
6Cloud Backup
Mysql WorkbenchOntap Select Deploy Administration Utility+3 more
Jun 17, 2026
Dec 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
5Apache
NetappOracle+2 more
6Cloud Backup
GuacamoleMysql Workbench+3 more
Jun 17, 2026
Dec 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
5Netapp
OracleSiemens+2 more
6Cloud Backup
Mysql WorkbenchOntap Select Deploy Administration Utility+3 more
Jun 17, 2026
Dec 9, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
7Canonical
DebianFedoraproject+4 more
9Debian Linux
Enterprise Manager Ops CenterFedora+6 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and...Show more
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).Show less
4Netapp
OracleSiemens+1 more
5Cloud Backup
Mysql WorkbenchOntap Select Deploy Administration Utility+2 more
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
4Debian
OpensuseOracle+1 more
5Debian Linux
LeapSolaris+2 more
Jun 17, 2026
Dec 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInf...Show more
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.Show less
4Debian
LinuxOpensuse+1 more
4Debian Linux
LeapLinux Kernel+1 more
Jun 17, 2026
Dec 3, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_fd.c driver, aka CID-30a8beeb3042.
3Gnu
NetappOracle
5Bash
Communications Cloud Native Core PolicyHci Management Node+2 more
Jun 17, 2026
Nov 28, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID...Show more
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.Show less
5Canonical
OracleRedhat+2 more
5Enterprise Linux
Mysql WorkbenchSinec Infrastructure Network Services+2 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
4Debian
OpensuseOracle+1 more
4Debian Linux
GraalvmLeap+1 more
Jun 17, 2026
Nov 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can explo...Show more
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.Show less
4Canonical
OracleSiemens+1 more
4Mysql Workbench
Sinec Infrastructure Network ServicesSqlite+1 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
4Canonical
Ibus ProjectOracle+1 more
4Enterprise Linux
IbusUbuntu Linux+1 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attac...Show more
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.Show less
7Broadcom
CanonicalFedoraproject+4 more
18Active Iq Unified Manager
Aff Baseboard Management ControllerBrocade Fabric Operating System Firmware+15 more
Jun 17, 2026
Nov 18, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.