Oracle
oracle
11,357 CVEs • 1,102 products
Products (1,102)
Click to collapseToggle
Products (1,102)
Click to collapse
CVEs (11,357)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian OracleRedhat+1 more4Communications Operations Monitor Debian LinuxOpenstack+1 moreNov 21, 2024 Jun 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. |
5Canonical DebianGnupg+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 13, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign functi...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jun 5, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jun 5, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypa...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jun 5, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control ch...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jun 5, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins. |
5Bouncycastle DebianNetapp+2 more20Api Gateway Bc JavaBusiness Process Management Suite+17 moreMay 12, 2025 Jun 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have l...Show more |
4Apache CanonicalDebian+1 more21Batik Business IntelligenceCommunications Diameter Signaling Router+18 moreJun 17, 2026 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was t...Show more |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreApr 15, 2026 May 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer...Show more |
2Dolibarr Oracle2Data Integrator DolibarrJun 17, 2026 May 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_lis...Show more |
12Arm CanonicalDebian+9 more282Atom C Atom EAtom X5 E3930+279 moreMay 29, 2026 May 22, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more |
3Apache DebianOracle3Debian Linux Goldengate Stream AnalyticsZookeeperJun 17, 2026 May 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and beg...Show more |
5Canonical GnuNetapp+2 more10Communications Session Border Controller Data Ontap EdgeElement Software Management+7 moreNov 21, 2024 May 18, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupp...Show more |
4Gnu NetappOracle+1 more9Communications Session Border Controller Data Ontap EdgeElement Software Management+6 moreNov 21, 2024 May 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leadin...Show more |
7Canonical DebianIjg+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreNov 21, 2024 May 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. |
5Netapp OraclePivotal Software+2 more42Agile Plm Application Testing SuiteBig Data Discovery+39 moreNov 21, 2024 May 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met...Show more |
3Oracle RedhatVmware30Agile Product Lifecycle Management Application Testing SuiteBig Data Discovery+27 moreNov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through t...Show more |
2Apache Oracle2Derby Weblogic ServerNov 21, 2024 May 7, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network...Show more |
3Google OracleRedhat17Banking Payments Communications Ip Service ActivatorCustomer Management And Segmentation Foundation+14 moreNov 21, 2024 Apr 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data,...Show more |
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Difficult to exploit vulnerabili...Show more |