CVE-2016-0530
published 2016-01-21CVE-2016-0530: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5…
PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.82%
76.5th percentile
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and CVE-2016-0529.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | customer_interaction_history | — | — |
| oracle | customer_interaction_history | — | — |
| oracle | customer_interaction_history | — | — |
| oracle | customer_interaction_history | — | — |
| oracle | customer_interaction_history | — | — |
| oracle | customer_interaction_history | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6hm-pf3c-83r3: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
ghsa_unreviewed·2022-05-17·CVSS 6.4
CVE-2016-0530 [MEDIUM] GHSA-f6hm-pf3c-83r3: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and CVE-2016-0529.
GHSA
GHSA-9792-xfjj-9v84: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
ghsa_unreviewed·2022-05-17·CVSS 6.4
CVE-2016-0528 [MEDIUM] GHSA-9792-xfjj-9v84: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0529, and CVE-2016-0530.
GHSA
GHSA-w3f9-9vr2-9j29: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
ghsa_unreviewed·2022-05-17·CVSS 6.4
CVE-2016-0529 [MEDIUM] GHSA-w3f9-9vr2-9j29: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0528, and CVE-2016-0530.
GHSA
GHSA-c5r9-rhv5-76mh: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
ghsa_unreviewed·2022-05-17·CVSS 6.4
CVE-2016-0527 [MEDIUM] GHSA-c5r9-rhv5-76mh: Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0528, CVE-2016-0529, and CVE-2016-0530.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8909 Qemu: audio: intel-hda: infinite loop in processing dma buffer stream
bugzilla·2016-10-24·CVSS 6.0
CVE-2016-8909 [MEDIUM] CVE-2016-8909 Qemu: audio: intel-hda: infinite loop in processing dma buffer stream
CVE-2016-8909 Qemu: audio: intel-hda: infinite loop in processing dma buffer stream
Quick Emulator(Qemu) built with the Intel HDA controller emulation support
is vulnerable to an infinite loop issue. It could occur while processing the
DMA buffer stream while doing data transfer in 'intel_hda_xfer'.
A privileged user inside guest could use this flaw to consume excessive CPU
cycles on the host, resulting in DoS.
Upstream patch
-> https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg04717.html
Discussion:
Acknowledgments:
Name: PSIRT (Huawei Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1388053]
---
commit 0c0fc2b5fd534786051889459848764edd798050
Author: Prasad J Pandit
Date: Thu Oct 20 13:10:24 2016 +0530
audio: intel-hda: check stream entry c
Bugzilla
CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation
bugzilla·2016-10-14·CVSS 6.0
CVE-2016-8668 [MEDIUM] CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation
CVE-2016-8668 Qemu: net: OOB buffer access in rocker switch emulation
Quick Emulator(Qemu) built with the Rocker switch emulation support is
vulnerable to an OOB read access issue. It could occur while performing a DMA
access 'TEST_DMA_CTRL_INVERT' test.
A privileged guest user could use this issue to crash the Qemu process instance
on the host resulting in DoS.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-10/msg02501.html
Discussion:
Acknowledgments:
Name: PSIRT (Huawei Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1384898]
---
CVE assignment:
http://seclists.org/oss-sec/2016/q4/141
---
commit 8caed3d564672e8bc6d2e4c6a35228afd01f4723
Author: Prasad J Pandit
Date: Wed Oct 12 14:40:55 2016 +0530
net: rocker: set limit t
Bugzilla
CVE-2016-7421 Qemu: scsi: pvscsi: infinite loop when processing IO requests
bugzilla·2016-09-16·CVSS 4.4
CVE-2016-7421 [MEDIUM] CVE-2016-7421 Qemu: scsi: pvscsi: infinite loop when processing IO requests
CVE-2016-7421 Qemu: scsi: pvscsi: infinite loop when processing IO requests
Quick Emulator(Qemu) built with the VMWARE PVSCSI paravirtual SCSI bus
emulation support is vulnerable to an infinite loop issue.
It could occur while processing SCSI IO requests.
A privileged user inside guest could use this flaw to crash the Qemu process
resulting in DoS.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg03609.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/09/16/3
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1376733]
---
Acknowledgements:
Name: Li Qiang, Victor V (360.cn Inc.)
---
commit d251157ac1928191af851d199a9ff255d330bec9
Author: Prasad J Pandit
Date: Wed Sep 14 15:09:12 2016 +0530
scsi: pvscsi: li
Bugzilla
CVE-2016-7156 Qemu: scsi: pvscsi: infintie loop when building SG list
bugzilla·2016-09-06·CVSS 4.4
CVE-2016-7156 [MEDIUM] CVE-2016-7156 Qemu: scsi: pvscsi: infintie loop when building SG list
CVE-2016-7156 Qemu: scsi: pvscsi: infintie loop when building SG list
Quick Emulator(Qemu) built with the VMWARE PVSCSI paravirtual SCSI bus
emulation support is vulnerable to an infinite loop issue. It could occur
while processing an IO request descriptor, building SG list.
A privileged user inside guest could use this flaw to crash the Qemu process
resulting in DoS.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg00772.html
Discussion:
Acknowledgments:
Name: Li Qiang (360.cn Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1373480]
---
I think this ended up as
commit 49adc5d3f8c6bb75e55ebfeab109c5c37dea65e8
Author: Prasad J Pandit
Date: Tue Sep 6 02:20:43 2016 +0530
scsi: pvscsi: limit loop to fetch SG list
2016-01-21
Published