Vulnerabilities > Oracle > Graalvm

DATE CVE VULNERABILITY TITLE RISK
2020-06-03 CVE-2020-11080 Improper Enforcement of Message or Data Structure vulnerability in multiple products
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service.
7.5
2020-04-15 CVE-2020-2900 Unspecified vulnerability in Oracle Graalvm 19.3.1/20.0.0
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools).
network
high complexity
oracle
3.6
2020-04-15 CVE-2020-2802 Unspecified vulnerability in Oracle Graalvm 19.3.1/20.0.0
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler).
network
low complexity
oracle
4.0
2020-04-15 CVE-2020-2799 Unspecified vulnerability in Oracle Graalvm 19.3.1/20.0.0
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler).
network
oracle
3.5
2020-03-30 CVE-2019-17561 Improper Verification of Cryptographic Signature vulnerability in multiple products
The "Apache NetBeans" autoupdate system does not fully validate code signatures.
network
low complexity
apache oracle CWE-347
5.0
2020-03-30 CVE-2019-17560 Improper Certificate Validation vulnerability in multiple products
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads.
network
low complexity
apache oracle CWE-295
critical
9.1
2020-02-07 CVE-2019-15606 Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
network
low complexity
nodejs oracle debian redhat opensuse
critical
9.8
2020-02-07 CVE-2019-15605 HTTP Request Smuggling vulnerability in multiple products
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
network
low complexity
nodejs debian fedoraproject opensuse redhat oracle CWE-444
critical
9.8
2020-02-07 CVE-2019-15604 Improper Certificate Validation vulnerability in multiple products
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
network
low complexity
nodejs debian opensuse redhat oracle CWE-295
7.5
2020-01-15 CVE-2020-2604 Deserialization of Untrusted Data vulnerability in multiple products
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization).
8.1