CVE-2014-2480NULL Pointer Dereference in Oracle Fusion Middleware

Severity
6.8MEDIUMNVD
EPSS
1.0%
top 22.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 17
Latest updateOct 20

Description

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-2481.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDoracle/fusion_middleware4 versions+3

🔴Vulnerability Details

3
OSV
fs/proc/task_mmu: check p->vec_buf for NULL2025-10-20
GHSA
GHSA-3wg4-74hw-hxr7: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 102022-05-14
CVEList
CVE-2014-2480: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 102014-07-17

📋Vendor Advisories

1
Red Hat
kernel: fs/proc/task_mmu: check p->vec_buf for NULL2025-10-20
CVE-2014-2480 — NULL Pointer Dereference in Oracle | cvebase