VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Oracle
>
Peoplesoft Enterprise Peopletools
> 8.58
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2021-07-13
CVE-2021-35517
Allocation of Resources Without Limits or Throttling vulnerability in multiple products
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs.
network
low complexity
apache
netapp
oracle
CWE-770
7.5
7.5
2021-07-13
CVE-2021-36090
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs.
network
low complexity
apache
oracle
netapp
7.5
7.5
2021-05-19
CVE-2021-3517
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11.
network
low complexity
xmlsoft
redhat
fedoraproject
debian
netapp
oracle
8.6
8.6
2021-05-18
CVE-2021-3518
Use After Free vulnerability in multiple products
There's a flaw in libxml2 in versions before 2.9.11.
network
low complexity
xmlsoft
debian
redhat
fedoraproject
netapp
oracle
CWE-416
8.8
8.8
2021-05-14
CVE-2021-3537
NULL Pointer Dereference vulnerability in multiple products
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference.
network
high complexity
xmlsoft
redhat
debian
fedoraproject
netapp
oracle
CWE-476
5.9
5.9
2021-03-25
CVE-2021-3450
Improper Certificate Validation vulnerability in multiple products
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain.
network
high complexity
openssl
freebsd
netapp
windriver
fedoraproject
tenable
oracle
mcafee
sonicwall
nodejs
CWE-295
7.4
7.4
2021-03-25
CVE-2021-3449
NULL Pointer Dereference vulnerability in multiple products
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.
network
high complexity
openssl
debian
freebsd
netapp
tenable
fedoraproject
mcafee
checkpoint
oracle
sonicwall
siemens
nodejs
CWE-476
5.9
5.9
2021-03-23
CVE-2021-21345
OS Command Injection vulnerability in multiple products
XStream is a Java library to serialize objects to XML and back again.
network
low complexity
netapp
apache
xstream
debian
fedoraproject
oracle
CWE-78
critical
9.9
9.9
2021-03-19
CVE-2021-27906
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file.
local
low complexity
apache
fedoraproject
oracle
5.5
5.5
2021-03-03
CVE-2021-22884
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”.
network
high complexity
nodejs
fedoraproject
netapp
oracle
siemens
7.5
7.5
«
Previous
1
2
...
3
4
5
(current)
6
7
...
9
10
»
Next