Vulnerability index

Browse CVEs

2,252 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Retail Store Inventory Management HIGH 8.8
CVE-2019-2880

Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security). The supported version that…

Mitigation only
Fix from $1,950 2020-04-15
Peoplesoft Enterprise Cost Center Common Application Objects MEDIUM 5.3
CVE-2020-2695

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Approval Framework). Supported vers…

Mitigation only
Fix from $1,600 2020-01-15
Enterprise Manager Base Platform MEDIUM 6.0
CVE-2020-2643

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System). Supported versions that are affec…

Mitigation only
Fix from $1,600 2020-01-15
Jdk HIGH 7.5
CVE-2012-4420

An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly i…

No fix yet
Fix from $1,950 2019-12-26
Secure Global Desktop MEDIUM 6.1
CVE-2018-19439EPSS 20%

XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4). helpwind…

No fix yet
Fix from $1,600 2018-12-13
Webcenter Interaction MEDIUM 5.4
CVE-2018-16958

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Servic…

Mitigation only
Fix from $1,600 2018-09-18
Webcenter Interaction MEDIUM 5.3
CVE-2018-16959

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile commun…

Mitigation only
Fix from $1,600 2018-09-18
Webcenter Interaction CRITICAL 9.8
CVE-2018-16957

The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Orac…

Mitigation only
Fix from $2,300 2018-09-18
Webcenter Interaction HIGH 8.8
CVE-2018-16952

The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its design. The impact is sensitiv…

Mitigation only
Fix from $1,950 2018-09-18
Webcenter Interaction MEDIUM 6.5
CVE-2018-16956

The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when processing page rename requests. Pa…

Mitigation only
Fix from $1,600 2018-09-18
Webcenter Interaction MEDIUM 6.1
CVE-2018-16953

The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cro…

Mitigation only
Fix from $1,600 2018-09-18
Webcenter Interaction MEDIUM 6.1
CVE-2018-16955

The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redi…

Mitigation only
Fix from $1,600 2018-09-18
Glassfish Server CRITICAL 9.8
CVE-2018-14324

The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This a…

Mitigation only
Fix from $2,300 2018-07-16
Linux HIGH 7.5
CVE-2015-7691EPSS 7%

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) vi…

Mitigation only
Fix from $1,950 2017-08-07
Linux HIGH 7.5
CVE-2015-7692EPSS 7%

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). …

Mitigation only
Fix from $1,950 2017-08-07
Linux HIGH 7.5
CVE-2015-7701EPSS 7%

Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2017-08-07
Linux MEDIUM 6.5
CVE-2015-7702EPSS 5%

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). …

Mitigation only
Fix from $1,600 2017-08-07
Linux HIGH 7.5
CVE-2015-7703

The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configurat…

Mitigation only
Fix from $1,950 2017-07-24
Glassfish Server CRITICAL 9.8
CVE-2017-1000030

Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possib…

Mitigation only
Fix from $2,300 2017-07-17
Glassfish Server HIGH 7.5
CVE-2017-1000028EPSS 99%

Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can …

No fix yet
Fix from $1,950 2017-07-17
Glassfish Server HIGH 7.5
CVE-2017-1000029EPSS 8%

Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include …

Mitigation only
Fix from $1,950 2017-07-17
Marketing HIGH 7.1
CVE-2017-3355

Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 1…

Mitigation only
Fix from $1,950 2017-04-25
Marketing HIGH 7.1
CVE-2017-3356

Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 1…

Mitigation only
Fix from $1,950 2017-04-25
One To One Fulfillment HIGH 7.1
CVE-2017-3434

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Audience workbench). Supported versions that a…

Mitigation only
Fix from $1,950 2017-04-25
Sun Zfs Storage Appliance Kit Software HIGH 8.8
CVE-2017-3578

Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems). The supported …

Mitigation only
Fix from $1,950 2017-04-24
Hospitality Opera 5 Property Services HIGH 7.1
CVE-2017-3574

Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA License code conf…

Mitigation only
Fix from $1,950 2017-04-24
Peoplesoft Enterprise Esettlements MEDIUM 6.5
CVE-2017-3570

Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: eSettlements). The supported version that is a…

Mitigation only
Fix from $1,600 2017-04-24
Peoplesoft Enterprise Campus Software Campus Community MEDIUM 6.5
CVE-2017-3577

Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks). The supported vers…

Mitigation only
Fix from $1,600 2017-04-24
Hospitality Opera 5 Property Services MEDIUM 6.1
CVE-2017-3573

Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Printing). Suppor…

Mitigation only
Fix from $1,600 2017-04-24
Hospitality Opera 5 Property Services MEDIUM 5.4
CVE-2017-3569

Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Business Events).…

Mitigation only
Fix from $1,600 2017-04-24