Vulnerabilities > Oracle > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2019-12406 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message.
network
low complexity
apache oracle CWE-770
6.5
2019-11-06 CVE-2010-4178 Insufficiently Protected Credentials vulnerability in multiple products
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
local
low complexity
oracle fedoraproject CWE-522
5.5
2019-10-23 CVE-2019-12415 XXE vulnerability in multiple products
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
local
low complexity
apache oracle CWE-611
5.5
2019-10-16 CVE-2019-3031 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
low complexity
oracle
6.0
2019-10-16 CVE-2019-3027 Unspecified vulnerability in Oracle Application Object Library
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login Help).
network
low complexity
oracle
5.3
2019-10-16 CVE-2019-3026 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
low complexity
oracle
6.5
2019-10-16 CVE-2019-3024 Unspecified vulnerability in Oracle Installed Base
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order).
network
low complexity
oracle
4.7
2019-10-16 CVE-2019-3023 Unspecified vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.56/8.57
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Stylesheet).
network
low complexity
oracle
4.7
2019-10-16 CVE-2019-3022 Unspecified vulnerability in Oracle Content Manager
Vulnerability in the Oracle Content Manager product of Oracle E-Business Suite (component: Content).
network
low complexity
oracle
5.8
2019-10-16 CVE-2019-3021 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
low complexity
oracle
6.5