Vulnerabilities > Oracle > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-06-20 CVE-2017-3167 Improper Authentication vulnerability in multiple products
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
network
low complexity
apache netapp redhat apple debian oracle CWE-287
critical
9.8
2017-05-23 CVE-2016-9843 The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
network
low complexity
zlib opensuse debian canonical oracle redhat apple netapp mariadb nodejs
critical
9.8
2017-05-23 CVE-2016-9841 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
network
low complexity
zlib opensuse debian canonical oracle redhat apple netapp nodejs
critical
9.8
2017-04-24 CVE-2017-3623 Unspecified vulnerability in Oracle Solaris
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC).
network
low complexity
oracle
critical
10.0
2017-04-24 CVE-2017-3553 Unspecified vulnerability in Oracle Identity Manager 11.1.2.3.0
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine).
network
low complexity
oracle
critical
9.9
2017-04-24 CVE-2017-3549 SQL Injection vulnerability in Oracle Scripting
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration).
network
low complexity
oracle CWE-89
critical
9.1
2017-04-24 CVE-2017-3510 Unspecified vulnerability in Oracle Solaris 11.3
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver).
network
low complexity
oracle
critical
9.6
2017-04-24 CVE-2017-3508 Unspecified vulnerability in Oracle Primavera Gateway
Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration).
network
low complexity
oracle
critical
9.1
2017-04-24 CVE-2017-3503 Unspecified vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access (Apache Commons BeanUtils)).
network
low complexity
oracle
critical
9.9
2017-04-24 CVE-2017-3234 Unspecified vulnerability in Oracle Automatic Service Request
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).
network
low complexity
oracle
critical
9.8