Oracle

Commerce Guided Search

52 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 17.10.2023 22:15:12
  • Last modified 21.11.2024 07:44:08

Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to...

  • EPSS 1.73%
  • Published 19.04.2022 21:15:16
  • Last modified 21.11.2024 06:44:46

Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access vi...

  • EPSS 0.98%
  • Published 04.03.2022 16:15:10
  • Last modified 21.11.2024 06:47:39

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote ...

Warning Exploit
  • EPSS 94.46%
  • Published 03.03.2022 22:15:08
  • Last modified 13.03.2025 15:40:47

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that...

Exploit
  • EPSS 2.4%
  • Published 01.02.2022 12:15:08
  • Last modified 23.05.2025 16:53:31

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resul...

  • EPSS 0.11%
  • Published 17.11.2021 20:15:10
  • Last modified 21.11.2024 06:25:38

CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML byp...

  • EPSS 0.06%
  • Published 17.11.2021 19:15:08
  • Last modified 21.11.2024 06:25:38

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML by...

  • EPSS 0.6%
  • Published 19.10.2021 15:15:07
  • Last modified 21.11.2024 06:14:43

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well...

  • EPSS 0.23%
  • Published 19.10.2021 15:15:07
  • Last modified 21.11.2024 06:14:42

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an...

Exploit
  • EPSS 0.19%
  • Published 29.09.2021 20:15:08
  • Last modified 21.11.2024 05:50:59

When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not ...