VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
> Oracle
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2021-12-08
CVE-2021-43527
Out-of-bounds Write vulnerability in multiple products
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures.
network
low complexity
mozilla
netapp
oracle
starwindsoftware
CWE-787
critical
9.8
9.8
2021-12-07
CVE-2021-42717
Uncontrolled Recursion vulnerability in multiple products
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.
network
low complexity
trustwave
f5
debian
oracle
CWE-674
7.5
7.5
2021-11-17
CVE-2021-41165
CKEditor4 is an open source WYSIWYG HTML editor.
network
low complexity
ckeditor
drupal
oracle
5.4
5.4
2021-11-17
CVE-2021-41164
CKEditor4 is an open source WYSIWYG HTML editor.
network
low complexity
ckeditor
drupal
oracle
fedoraproject
5.4
5.4
2021-11-17
CVE-2021-43976
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
low complexity
linux
fedoraproject
debian
netapp
oracle
4.6
4.6
2021-11-15
CVE-2021-22959
HTTP Request Smuggling vulnerability in multiple products
The parser in accepts requests with a space (SP) right after the header name before the colon.
network
low complexity
llhttp
oracle
debian
CWE-444
6.5
6.5
2021-11-10
CVE-2021-3572
A flaw was found in python-pip in the way it handled Unicode separators in git references.
network
low complexity
pypa
oracle
5.7
5.7
2021-11-08
CVE-2021-41772
Improper Input Validation vulnerability in multiple products
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
network
low complexity
golang
fedoraproject
oracle
CWE-20
7.5
7.5
2021-11-04
CVE-2021-43396
In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset.
network
low complexity
gnu
oracle
7.5
7.5
2021-11-04
CVE-2021-43389
Out-of-bounds Read vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.14.15.
local
low complexity
linux
redhat
debian
oracle
CWE-125
5.5
5.5
«
Previous
1
2
...
23
24
25
(current)
26
27
...
455
456
»
Next