Oracle

Oss Support Tools

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.61%
  • Veröffentlicht 16.09.2019 19:15:10
  • Zuletzt bearbeitet 16.04.2026 15:16:40

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

  • EPSS 0.99%
  • Veröffentlicht 02.07.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:44:56

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privile...

Exploit
  • EPSS 15.48%
  • Veröffentlicht 28.05.2019 19:29:06
  • Zuletzt bearbeitet 15.04.2026 21:17:01

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

  • EPSS 25.59%
  • Veröffentlicht 18.01.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 02:40:09

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

  • EPSS 1.5%
  • Veröffentlicht 18.01.2018 02:29:19
  • Zuletzt bearbeitet 21.11.2024 04:04:03

Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Diagnostic Assistant). The supported version that is affected is Prior to 2.11.33. Easily exploitable vulnerability allows unauthenticated attacker with network a...

  • EPSS 5.81%
  • Veröffentlicht 18.01.2018 02:29:19
  • Zuletzt bearbeitet 21.11.2024 04:04:03

Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Diagnostic Assistant). The supported version that is affected is Prior to 2.11.33. Easily exploitable vulnerability allows low privileged attacker with network ac...

  • EPSS 0.71%
  • Veröffentlicht 18.01.2018 02:29:19
  • Zuletzt bearbeitet 21.11.2024 04:04:03

Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Diagnostic Assistant). The supported version that is affected is Prior to 2.11.33. Easily exploitable vulnerability allows low privileged attacker with network ac...

Exploit
  • EPSS 1.4%
  • Veröffentlicht 15.03.2017 16:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

  • EPSS 14.2%
  • Veröffentlicht 15.02.2016 02:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 tra...