CVE-2020-9314
- EPSS 31.34%
- Veröffentlicht 10.05.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:23
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE...
CVE-2020-9315
- EPSS 88.02%
- Veröffentlicht 10.05.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:40:23
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support...
CVE-2017-10055
- EPSS 0.39%
- Veröffentlicht 19.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with ...
CVE-2016-1950
- EPSS 3.01%
- Veröffentlicht 13.03.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via ...
CVE-2015-7182
- EPSS 24.24%
- Veröffentlicht 05.11.2015 05:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause ...
CVE-2013-1620
- EPSS 0.81%
- Veröffentlicht 08.02.2013 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct di...
- EPSS 1.12%
- Veröffentlicht 17.07.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server.