Vulnerabilities > Oracle > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-16 CVE-2019-2400 Unspecified vulnerability in Oracle E-Business Suite
Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registration).
network
low complexity
oracle
8.2
2019-01-16 CVE-2018-3311 Unspecified vulnerability in Oracle Retail Xstore Payment 3.3
Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security).
network
low complexity
oracle
8.6
2019-01-16 CVE-2018-3309 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).
local
low complexity
oracle
8.2
2019-01-11 CVE-2018-16865 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. 7.8
2019-01-11 CVE-2018-16864 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. 7.8
2019-01-07 CVE-2018-1320 Improper Certificate Validation vulnerability in multiple products
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class.
network
low complexity
apache debian f5 oracle CWE-295
7.5
2018-12-05 CVE-2018-19754 Missing Authorization vulnerability in Oracle Tarantella Enterprise
Tarantella Enterprise before 3.11 allows bypassing Access Control.
network
low complexity
oracle CWE-862
8.8
2018-12-05 CVE-2018-19753 Path Traversal vulnerability in Oracle Tarantella Enterprise
Tarantella Enterprise before 3.11 allows Directory Traversal.
network
low complexity
oracle CWE-22
7.5
2018-11-16 CVE-2018-15769 RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue.
network
low complexity
dell oracle
7.5
2018-10-26 CVE-2018-15686 Deserialization of Untrusted Data vulnerability in multiple products
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess.
7.8