Vulnerabilities > Oracle > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-28196 Uncontrolled Recursion vulnerability in multiple products
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
network
low complexity
mit fedoraproject netapp oracle CWE-674
7.5
2020-10-30 CVE-2020-7760 Resource Exhaustion vulnerability in multiple products
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2.
network
low complexity
codemirror oracle CWE-400
7.5
2020-10-23 CVE-2020-27216 In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system.
local
high complexity
eclipse netapp oracle apache debian
7.0
2020-10-21 CVE-2020-14883 Unspecified vulnerability in Oracle Weblogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
network
low complexity
oracle
7.2
2020-10-21 CVE-2020-14880 Unspecified vulnerability in Oracle Business Intelligence Publisher
Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).
network
low complexity
oracle
8.5
2020-10-21 CVE-2020-14879 Unspecified vulnerability in Oracle Business Intelligence Publisher
Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).
network
low complexity
oracle
8.5
2020-10-21 CVE-2020-14878 Unspecified vulnerability in Oracle Mysql
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).
low complexity
oracle
8.0
2020-10-21 CVE-2020-14872 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
low complexity
oracle
8.2
2020-10-21 CVE-2020-14865 Unspecified vulnerability in Oracle Peoplesoft Enterprise SCM Esupplier Connection 9.2
Vulnerability in the PeopleSoft Enterprise SCM eSupplier Connection product of Oracle PeopleSoft (component: eSupplier Connection).
network
low complexity
oracle
8.1
2020-10-21 CVE-2020-14864 Path Traversal vulnerability in Oracle Business Intelligence 12.2.1.3.0/12.2.1.4.0/5.5.0.0.0
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation).
network
low complexity
oracle CWE-22
7.5