Vulnerabilities > Oracle > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-25 CVE-2021-21703 Out-of-bounds Write vulnerability in multiple products
In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.
local
high complexity
php debian fedoraproject netapp oracle CWE-787
7.0
2021-10-20 CVE-2021-35599 Unspecified vulnerability in Oracle Zero Downtime DB Migration to Cloud 21C
Vulnerability in the Zero Downtime DB Migration to Cloud component of Oracle Database Server.
local
low complexity
oracle
8.2
2021-10-20 CVE-2021-35560 Vulnerability in the Java SE product of Oracle Java SE (component: Deployment).
network
high complexity
oracle netapp
7.5
2021-10-20 CVE-2021-35562 Unspecified vulnerability in Oracle Universal Work Queue
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration).
network
low complexity
oracle
8.1
2021-10-20 CVE-2021-35563 Unspecified vulnerability in Oracle Shipping Execution 12.2.10/12.2.6
Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Workflow Events).
network
low complexity
oracle
8.1
2021-10-20 CVE-2021-35566 Unspecified vulnerability in Oracle Applications Manager
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics).
network
low complexity
oracle
8.1
2021-10-20 CVE-2021-35570 Unspecified vulnerability in Oracle Mobile Field Service
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Admin UI).
network
low complexity
oracle
8.1
2021-10-20 CVE-2021-35572 Unspecified vulnerability in Oracle Outside in Technology 8.5.5
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).
network
low complexity
oracle
7.5
2021-10-20 CVE-2021-35573 Unspecified vulnerability in Oracle Outside in Technology 8.5.5
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).
network
low complexity
oracle
7.5
2021-10-20 CVE-2021-35574 Unspecified vulnerability in Oracle products
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters).
network
low complexity
oracle
7.5