Oracle

Outside In Technology

195 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 05.01.2021 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:21:55

There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw ...

  • EPSS 0.08%
  • Veröffentlicht 05.01.2021 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:54

There's a flaw in openjpeg in versions prior to 2.4.0 in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to...

  • EPSS 0.22%
  • Veröffentlicht 29.06.2020 21:15:14
  • Zuletzt bearbeitet 21.11.2024 05:05:28

jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to c...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 27.06.2020 12:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:24

In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.

  • EPSS 0.03%
  • Veröffentlicht 27.05.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:01:38

ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.

  • EPSS 0.08%
  • Veröffentlicht 27.05.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:38

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

  • EPSS 0.09%
  • Veröffentlicht 27.05.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:38

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 24.05.2020 22:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:15

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

  • EPSS 0.98%
  • Veröffentlicht 15.04.2020 14:15:27
  • Zuletzt bearbeitet 21.11.2024 05:26:15

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access ...

  • EPSS 0.93%
  • Veröffentlicht 15.04.2020 14:15:27
  • Zuletzt bearbeitet 21.11.2024 05:26:15

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network acce...