CVE-2016-0525
published 2016-01-21CVE-2016-0525: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.75%
75.2th percentile
Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Work Provider Administration.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | universal_work_queue | — | — |
| oracle | universal_work_queue | — | — |
| oracle | universal_work_queue | — | — |
| oracle | universal_work_queue | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5rx-2c36-m948: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11
ghsa_unreviewed·2022-05-17
CVE-2016-0525 [MEDIUM] GHSA-f5rx-2c36-m948: Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Work Provider Administration.
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3679 chromium-browser: multiple unspecified vulnerabilities
bugzilla·2016-03-30·CVSS 8.8
CVE-2016-3679 [HIGH] CVE-2016-3679 chromium-browser: multiple unspecified vulnerabilities
CVE-2016-3679 chromium-browser: multiple unspecified vulnerabilities
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
References:
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-3679.html
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3679
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0525 https://rhn.redhat.com/errata/RHSA-2016-0525.html
Bugzilla
CVE-2016-1646 chromium-browser: out-of-bounds read in V8
bugzilla·2016-03-29·CVSS 8.8
CVE-2016-1646 [HIGH] CVE-2016-1646 chromium-browser: out-of-bounds read in V8
CVE-2016-1646 chromium-browser: out-of-bounds read in V8
A out-of-bounds read flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=594574
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0525 https://rhn.redhat.com/errata/RHSA-2016-0525.html
Bugzilla
CVE-2016-1648 chromium-browser: use-after-free in Extensions
bugzilla·2016-03-29·CVSS 8.8
CVE-2016-1648 [HIGH] CVE-2016-1648 chromium-browser: use-after-free in Extensions
CVE-2016-1648 chromium-browser: use-after-free in Extensions
A use-after-free flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=590455
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0525 https://rhn.redhat.com/errata/RHSA-2016-0525.html
Bugzilla
CVE-2016-1650 chromium-browser: various fixes from internal audits
bugzilla·2016-03-29·CVSS 8.8
CVE-2016-1650 [HIGH] CVE-2016-1650 chromium-browser: various fixes from internal audits
CVE-2016-1650 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=597518
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0525 https://rhn.redhat.com/errata/RHSA-2016-0525.html
Bugzilla
CVE-2016-1647 chromium-browser: use-after-free in Navigation
bugzilla·2016-03-29·CVSS 8.8
CVE-2016-1647 [HIGH] CVE-2016-1647 chromium-browser: use-after-free in Navigation
CVE-2016-1647 chromium-browser: use-after-free in Navigation
A use-after-free flaw was found in the Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=590284
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0525 https://rhn.redhat.com/errata/RHSA-2016-0525.html
Bugzilla
CVE-2016-1649 chromium-browser: buffer overflow in libANGLE
bugzilla·2016-03-29·CVSS 8.8
CVE-2016-1649 [HIGH] CVE-2016-1649 chromium-browser: buffer overflow in libANGLE
CVE-2016-1649 chromium-browser: buffer overflow in libANGLE
A buffer overflow flaw was found in the libANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=595836
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0525 https://rhn.redhat.com/errata/RHSA-2016-0525.html
2016-01-21
Published