VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Oracle
>
Enterprise Communications Broker
> 3.3.0
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2021-08-24
CVE-2021-3711
Classic Buffer Overflow vulnerability in multiple products
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt().
network
low complexity
openssl
debian
netapp
oracle
tenable
CWE-120
critical
9.8
9.8
2021-08-24
CVE-2021-3712
Out-of-bounds Read vulnerability in multiple products
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length.
network
high complexity
openssl
debian
netapp
mcafee
tenable
oracle
siemens
CWE-125
7.4
7.4
2021-06-01
CVE-2021-23017
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
network
high complexity
f5
openresty
fedoraproject
netapp
oracle
7.7
7.7
2021-02-15
CVE-2021-23337
Code Injection vulnerability in multiple products
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
network
low complexity
lodash
oracle
netapp
siemens
CWE-94
7.2
7.2
2021-02-15
CVE-2020-28500
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
network
low complexity
lodash
oracle
siemens
5.3
5.3
2020-07-15
CVE-2020-8203
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
network
high complexity
lodash
oracle
7.4
7.4