Oracle
oracle
11,357 CVEs • 1,102 products
Products (1,102)
Click to collapseToggle
Products (1,102)
Click to collapse
CVEs (11,357)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Oracle Vmware25Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+22 moreNov 21, 2024 Apr 6, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (ser...Show more |
2Oracle Vmware28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static reso...Show more |
4Debian OracleRedhat+1 more28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
6Canonical DebianLinux+3 more12Communications Eagle Application Processor Debian LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Mar 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user. |
3Oracle QosRedhat13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreJun 17, 2026 Mar 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has b...Show more |
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code o...Show more |
3Oracle RedhatVmware5Fuse Rapid PlanningRetail Xstore Point Of Service+2 moreNov 21, 2024 Mar 16, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing secu...Show more |
2Apache Oracle3Commons Compress Mysql ClusterWeblogic ServerNov 21, 2024 Mar 16, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used...Show more |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreNov 21, 2024 Mar 14, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreNov 21, 2024 Mar 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreNov 21, 2024 Mar 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse. |
6Canonical HpeNetapp+3 more16Diskstation Manager Fujitsu M10 1 FirmwareFujitsu M10 4 Firmware+13 moreJun 17, 2026 Mar 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side"...Show more |
5Apache CanonicalDebian+2 more10Debian Linux Fusion MiddlewareHospitality Guest Access+7 moreNov 21, 2024 Feb 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of...Show more |
4Debian FasterxmlOracle+1 more5Communications Billing And Revenue Management Communications Instant Messaging ServerDebian Linux+2 moreJun 17, 2026 Feb 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploi...Show more |
4Apache CanonicalDebian+1 more6Debian Linux Fusion MiddlewareManaged File Transfer+3 moreNov 21, 2024 Feb 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security cons...Show more |
2Belitsoft Oracle2Checklist Data IntegratorJun 17, 2026 Feb 22, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter. |
2Joyent Oracle3Smartos SolarisZfs Storage ApplianceNov 21, 2024 Feb 21, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code o...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsJun 17, 2026 Feb 20, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Feb 16, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that sh...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Feb 16, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the res...Show more |