Vulnerabilities > Oracle

DATE CVE VULNERABILITY TITLE RISK
2020-07-15 CVE-2020-14531 Unspecified vulnerability in Oracle Siebel UI Framework
Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server).
network
high complexity
oracle
5.9
2020-07-15 CVE-2020-14530 Unspecified vulnerability in Oracle Security Service 11.1.1.9.0
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: None).
network
high complexity
oracle
5.9
2020-07-15 CVE-2020-14529 Unspecified vulnerability in Oracle Primavera Portfolio Management
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module).
network
low complexity
oracle
5.4
2020-07-15 CVE-2020-14528 Unspecified vulnerability in Oracle Primavera Portfolio Management
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).
network
low complexity
oracle
6.1
2020-07-15 CVE-2020-14527 Unspecified vulnerability in Oracle Primavera Portfolio Management
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access).
network
high complexity
oracle
5.9
2020-07-15 CVE-2020-8203 Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
network
high complexity
lodash oracle
7.4
2020-07-14 CVE-2020-13935 Infinite Loop vulnerability in multiple products
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104.
7.5
2020-07-14 CVE-2020-13934 Memory Leak vulnerability in multiple products
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2.
7.5
2020-07-14 CVE-2020-15719 Improper Certificate Validation vulnerability in multiple products
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support.
network
high complexity
openldap redhat opensuse mcafee oracle CWE-295
4.2
2020-07-13 CVE-2019-20907 Infinite Loop vulnerability in multiple products
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
7.5