← Back

Oracle

oracle

11,395 CVEs • 1,102 products

Products (1,102)

Click to collapse
Toggle
Mysql
mysql
Jre
jre
Jdk
jdk
Solaris
solaris
Mysql Server
mysql_server
Linux
linux
Graalvm
graalvm
Http Server
http_server
Jrockit
jrockit
Siebel Crm
siebel_crm
Openjdk
openjdk
Mysql Cluster
mysql_cluster
Agile Plm
agile_plm
Marketing
marketing
Database
database
Javafx
javafx
Coherence
coherence
Oracle9i
oracle9i
Berkeley Db
berkeley_db
Oracle8i
oracle8i
Istore
istore
Bi Publisher
bi_publisher

CVEs (11,395)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Mozilla
Oracle
2Firefox
Solaris
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an i...Show more
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.Show less
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object tha...Show more
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.Show less
5Canonical
FedoraprojectGnome+2 more
5Fedora
Gdk PixbufOpensuse+2 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other produ...Show more
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.Show less
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wil...Show more
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.Show less
4Canonical
MozillaOpensuse+1 more
5Firefox
Firefox OsOpensuse+2 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified o...Show more
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.Show less
4Canonical
MozillaOpensuse+1 more
5Firefox
Firefox OsOpensuse+2 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a...Show more
Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.Show less
4Canonical
MozillaOpensuse+1 more
5Firefox
Firefox OsOpensuse+2 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly hav...Show more
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."Show less
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed...Show more
The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data.Show less
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.
4Canonical
MozillaOpensuse+1 more
4Firefox
OpensuseSolaris+1 more
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash...Show more
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.Show less
3Mozilla
OpensuseOracle
3Firefox
OpensuseSolaris
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.
3Mozilla
OpensuseOracle
3Firefox
OpensuseSolaris
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (...Show more
mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (aka MAR) file.Show less
3Mozilla
OpensuseOracle
3Firefox
OpensuseSolaris
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors inv...Show more
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.Show less
8Apple
CanonicalDebian+5 more
12Debian Linux
Enterprise LinuxFedora+9 more
May 6, 2026
Aug 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
2Apache
Oracle
3Activemq
Business Intelligence PublisherFusion Middleware
May 6, 2026
Aug 14, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
2Apache
Oracle
6Groovy
Health Sciences Clinical Development CenterRetail Order Broker Cloud Service+3 more
May 6, 2026
Aug 13, 2015
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
7Arista
DebianFedoraproject+4 more
24Debian Linux
Enterprise Linux Compute Node EusEnterprise Linux Desktop+21 more
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
6Canonical
MozillaOpensuse+3 more
15Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+12 more
Apr 22, 2026
Aug 8, 2015
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vector...Show more
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.Show less
8Canonical
DebianGoogle+5 more
13Chrome
Debian LinuxLeap+10 more
May 6, 2026
Jul 23, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer ove...Show more
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.Show less