Vulnerabilities > Oracle > Database Server

DATE CVE VULNERABILITY TITLE RISK
2019-01-02 CVE-2018-14719 Deserialization of Untrusted Data vulnerability in multiple products
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
network
low complexity
fasterxml debian oracle redhat netapp CWE-502
critical
9.8
2018-12-20 CVE-2018-1000873 Improper Input Validation vulnerability in multiple products
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS).
network
low complexity
fasterxml oracle netapp CWE-20
6.5
2018-10-17 CVE-2018-3259 Unspecified vulnerability in Oracle Database Server
Vulnerability in the Java VM component of Oracle Database Server.
network
low complexity
oracle
7.5
2018-08-10 CVE-2018-3110 Unspecified vulnerability in Oracle Database Server
A vulnerability was discovered in the Java VM component of Oracle Database Server.
network
low complexity
oracle
6.5
2018-07-18 CVE-2018-3004 Unspecified vulnerability in Oracle Database Server
Vulnerability in the Java VM component of Oracle Database Server.
network
oracle
3.5
2018-07-18 CVE-2018-2939 Unspecified vulnerability in Oracle Database Server
Vulnerability in the Core RDBMS component of Oracle Database Server.
local
low complexity
oracle
3.6
2018-04-26 CVE-2018-10237 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
network
high complexity
google redhat oracle CWE-770
5.9
2018-04-19 CVE-2018-2841 Unspecified vulnerability in Oracle Database Server
Vulnerability in the Java VM component of Oracle Database Server.
network
oracle
6.0
2018-02-06 CVE-2017-15095 Deserialization of Untrusted Data vulnerability in multiple products
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
network
low complexity
fasterxml debian redhat netapp oracle CWE-502
critical
9.8
2018-01-18 CVE-2018-2680 Unspecified vulnerability in Oracle Database Server 11.2.0.4/12.1.0.2/12.2.0.1
Vulnerability in the Java VM component of Oracle Database Server.
network
high complexity
oracle
5.1