Oracle
Oracle Enterprise Communications Broker: vulnerabilidades y CVE
Oracle Enterprise Communications Broker tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-3712 | Alta (7.4) | 50% | — | 24 ago 2021 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are… |
| CVE-2021-3711 | Crítica (9.8) | 88% | — | 24 ago 2021 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be… |
| CVE-2021-23017 | Alta (7.7) | 53% | — | 1 jun 2021 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential… |
| CVE-2021-29425 | Media (4.8) | 9.9% | — | 13 abr 2021 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to… |
| CVE-2021-23337 | Alta (7.2) | 21% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
| CVE-2020-28500 | Media (5.3) | 7.3% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. |
| CVE-2020-1971 | Media (5.9) | 7.1% | — | 8 dic 2020 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances… |
| CVE-2020-14722 | Media (5.8) | 0.90% | — | 15 jul 2020 | Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Difficult to exploit vulnerability… |
| CVE-2020-14721 | Media (6.3) | 0.96% | — | 15 jul 2020 | Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitable vulnerability… |
| CVE-2020-14563 | Media (6.1) | 0.96% | — | 15 jul 2020 | Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Easily exploitable vulnerability… |
| CVE-2020-8203 | Alta (7.4) | 5.2% | — | 15 jul 2020 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |
| CVE-2020-11080 | Alta (7.5) | 5.3% | — | 3 jun 2020 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400… |
| CVE-2020-10726 | Media (4.4) | 0.47% | — | 20 may 2020 | A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file… |
| CVE-2020-10725 | Alta (7.7) | 2.2% | — | 20 may 2020 | A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for… |
| CVE-2020-10723 | Media (6.7) | 0.38% | — | 19 may 2020 | A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into… |
| CVE-2020-10722 | Media (6.7) | 0.38% | — | 19 may 2020 | A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption. |
| CVE-2019-10219 | Media (6.1) | 2.2% | — | 8 nov 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can… |
| CVE-2019-9513 | Alta (7.5) | 82% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that… |
| CVE-2019-9511 | Alta (7.5) | 60% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified… |
| CVE-2018-16865 | Alta (7.8) | 3.0% | — | 11 ene 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a… |
| CVE-2018-16864 | Alta (7.8) | 0.71% | — | 11 ene 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local… |
| CVE-2018-11237 | Alta (7.8) | 0.88% | — | 18 may 2018 | An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in… |
| CVE-2018-11236 | Crítica (9.8) | 7.1% | — | 18 may 2018 | stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures,… |
| CVE-2018-6485 | Crítica (9.8) | 4.7% | — | 1 feb 2018 | An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too… |
| CVE-2016-3516 | Baja (3.1) | 1.7% | — | 21 jul 2016 | Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors… |
| CVE-2016-3515 | Alta (7.5) | 3.8% | — | 21 jul 2016 | Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote attackers to affect confidentiality via unknown vectors. |
| CVE-2016-3514 | Media (6.5) | 2.7% | — | 21 jul 2016 | Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors… |
| CVE-2014-9708 | Media (5) | 56% | — | 31 mar 2015 | Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,". |