Oracle

Agile Product Lifecycle Management

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung
  • EPSS 100%
  • Veröffentlicht 18.12.2021 12:15:07
  • Zuletzt bearbeitet 25.08.2026 16:28:27

Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service wh...

  • EPSS 1.47%
  • Veröffentlicht 17.11.2021 20:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:38

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML byp...

  • EPSS 1.26%
  • Veröffentlicht 17.11.2021 19:15:08
  • Zuletzt bearbeitet 25.08.2026 16:28:27

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML by...

  • EPSS 1.69%
  • Veröffentlicht 10.11.2021 18:15:09
  • Zuletzt bearbeitet 25.08.2026 16:28:27

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrit...

Exploit
  • EPSS 39.36%
  • Veröffentlicht 26.10.2021 15:15:10
  • Zuletzt bearbeitet 25.08.2026 16:28:27

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any str...

Exploit
  • EPSS 8.53%
  • Veröffentlicht 26.10.2021 15:15:10
  • Zuletzt bearbeitet 25.08.2026 16:28:27

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The v...

  • EPSS 40.77%
  • Veröffentlicht 26.10.2021 15:15:10
  • Zuletzt bearbeitet 25.08.2026 16:28:27

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string v...

  • EPSS 7.38%
  • Veröffentlicht 19.09.2021 18:15:07
  • Zuletzt bearbeitet 25.08.2026 16:28:27

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacke...

Exploit
  • EPSS 2.5%
  • Veröffentlicht 21.07.2021 15:15:21
  • Zuletzt bearbeitet 25.08.2026 16:28:27

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracl...

  • EPSS 2.53%
  • Veröffentlicht 14.07.2021 07:15:08
  • Zuletzt bearbeitet 25.08.2026 16:28:27

When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prio...