Oracle
oracle
11,323 CVEs • 1,102 products
Products (1,102)
Click to collapseToggle
Products (1,102)
Click to collapse
CVEs (11,323)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oracle 1Retail Xstore Office Nov 21, 2024 Jul 23, 2019 N/A· v4 5.5 MEDIUM· v3 6.0 MEDIUM· v2 Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operations). Supported versions that are affected are 7.0 and 7.1. Easily exploitable vulnerability allows...Show more |
2Oracle Xstream10Banking Platform Business Activity MonitoringCommunications Billing And Revenue Management Elastic Charging Engine+7 moreJun 17, 2026 Jul 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary...Show more |
2Davegamble Oracle2Cjson Timesten In Memory DatabaseJun 17, 2026 Jul 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitiv...Show more |
6Canonical DebianFedoraproject+3 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreJun 17, 2026 Jul 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment...Show more |
5Canonical DebianOracle+2 more9Communications Operations Monitor Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attac...Show more |
5Canonical DebianOracle+2 more10Communications Operations Monitor Debian LinuxEnterprise Linux+7 moreJun 17, 2026 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command,...Show more |
3Libpng NetappOracle5Active Iq Unified Manager Hyperion Infrastructure TechnologyLibpng+2 moreNov 21, 2024 Jul 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png. |
3Fasterxml OracleRedhat7Clusterware Communications Instant Messaging ServerGlobal Lifecycle Management Opatch+4 moreNov 21, 2024 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. |
3Haxx NetappOracle9Curl Enterprise Manager Ops CenterHttp Server+6 moreJun 17, 2026 Jul 2, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If tha...Show more |
7Apple CanonicalFedoraproject+4 more25Active Iq Unified Manager Cloud BackupClustered Data Ontap+22 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more4Fedora Mod Auth MellonUbuntu Linux+1 moreJun 17, 2026 Jun 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. |
4Debian OpensuseOracle+1 more5Database Server Debian LinuxLeap+2 moreJun 17, 2026 Jun 26, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is s...Show more |
7Canonical DebianFedoraproject+4 more9Debian Linux FedoraHospitality Res 3700+6 moreMay 30, 2025 Jun 24, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for de...Show more |
1Oracle 9Communications Diameter Signaling Router Communications Network IntegrityHyperion Infrastructure Technology+6 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerabi...Show more |
2Oracle Pivotal Software2Banking Corporate Lending Spring Security OauthJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an...Show more |
6Apache CanonicalFedoraproject+3 more11Communications Session Report Manager Communications Session Route ManagerEnterprise Manager Ops Center+8 moreJun 17, 2026 Jun 11, 2019 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the fir...Show more |
4Canonical FedoraprojectOracle+1 more5Fedora SolarisTwisted+2 moreJun 17, 2026 Jun 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF. |
7Debian F5Fedoraproject+4 more11Debian Linux Enterprise Manager Ops CenterFedora+8 moreJun 17, 2026 May 28, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
2Apache Oracle5Camel Enterprise Data QualityEnterprise Manager Base Platform+2 moreJun 17, 2026 May 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed. |