Vulnerabilities > Oracle

DATE CVE VULNERABILITY TITLE RISK
2012-10-16 CVE-2012-1532 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
network
low complexity
oracle sun
critical
10.0
2012-10-16 CVE-2012-1531 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier; and JavaFX 2.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
network
low complexity
oracle sun
critical
10.0
2012-09-25 CVE-2012-2199 Resource Management Errors vulnerability in IBM Websphere MQ
The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.
network
low complexity
ibm oracle CWE-399
5.0
2012-09-21 CVE-2012-3137 Improper Authentication vulnerability in Oracle products
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vulnerability."
network
low complexity
oracle CWE-287
6.4
2012-09-15 CVE-2011-5167 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
network
oracle tidestone CWE-119
critical
9.3
2012-08-30 CVE-2012-3136 Remote Code Execution vulnerability in Oracle JDK and JRE
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-1682.
network
low complexity
oracle
critical
10.0
2012-08-30 CVE-2012-1682 Remote Code Execution vulnerability in Oracle JDK and JRE
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136.
network
low complexity
oracle
critical
10.0
2012-08-17 CVE-2012-2750 Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533.
network
low complexity
oracle mariadb debian
critical
10.0
2012-08-17 CVE-2012-2749 Resource Management Errors vulnerability in multiple products
MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
network
low complexity
mysql oracle CWE-399
4.0
2012-08-17 CVE-2012-2102 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
network
mysql oracle CWE-119
3.5