Oracle
Oracle Communications Session Border Controller: vulnerabilidades y CVE
Oracle Communications Session Border Controller tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-2416 | Media (4.9) | 0.93% | — | 20 oct 2021 | Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows… |
| CVE-2021-2414 | Media (6.8) | 1.2% | — | 20 oct 2021 | Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows… |
| CVE-2021-3712 | Alta (7.4) | 50% | — | 24 ago 2021 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are… |
| CVE-2021-3711 | Crítica (9.8) | 88% | — | 24 ago 2021 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be… |
| CVE-2021-33909 | Alta (7.8) | 9.7% | — | 20 jul 2021 | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged… |
| CVE-2021-23017 | Alta (7.7) | 53% | — | 1 jun 2021 | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential… |
| CVE-2021-23337 | Alta (7.2) | 21% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
| CVE-2020-28500 | Media (5.3) | 7.3% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. |
| CVE-2020-1971 | Media (5.9) | 7.1% | — | 8 dic 2020 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances… |
| CVE-2020-8203 | Alta (7.4) | 5.2% | — | 15 jul 2020 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |
| CVE-2020-10723 | Media (6.7) | 0.38% | — | 19 may 2020 | A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into… |
| CVE-2020-10722 | Media (6.7) | 0.38% | — | 19 may 2020 | A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption. |
| CVE-2019-10219 | Media (6.1) | 2.2% | — | 8 nov 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can… |
| CVE-2019-5482 | Crítica (9.8) | 18% | — | 16 sept 2019 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. |
| CVE-2019-5481 | Crítica (9.8) | 7.5% | — | 16 sept 2019 | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. |
| CVE-2019-1559 | Media (5.9) | 17% | — | 27 feb 2019 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte… |
| CVE-2018-16865 | Alta (7.8) | 3.0% | — | 11 ene 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a… |
| CVE-2018-16864 | Alta (7.8) | 0.71% | — | 11 ene 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local… |
| CVE-2018-11237 | Alta (7.8) | 0.88% | — | 18 may 2018 | An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in… |
| CVE-2018-11236 | Crítica (9.8) | 7.1% | — | 18 may 2018 | stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures,… |
| CVE-2018-6485 | Crítica (9.8) | 4.7% | — | 1 feb 2018 | An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too… |
| CVE-2015-0235 | Alta (10) | 95% | — | 28 ene 2015 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1)… |