CVE-2016-0700
published 2016-04-21CVE-2016-0700: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect…
PriorityP431medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.91%
77.6th percentile
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cj79-h84r-2v9c: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-14·CVSS 6.1
CVE-2016-0700 [MEDIUM] GHSA-cj79-h84r-2v9c: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675.
GHSA
GHSA-38wj-mm25-rhw6: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-14·CVSS 6.1
CVE-2016-0675 [MEDIUM] GHSA-38wj-mm25-rhw6: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9845 Qemu: display: virtio-gpu-3d: information leakage in virgl_cmd_get_capset_info
bugzilla·2016-12-07·CVSS 6.5
CVE-2016-9845 [MEDIUM] CVE-2016-9845 Qemu: display: virtio-gpu-3d: information leakage in virgl_cmd_get_capset_info
CVE-2016-9845 Qemu: display: virtio-gpu-3d: information leakage in virgl_cmd_get_capset_info
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is
vulnerable to an information leakage issue. It could occur while processing
'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command.
A guest user/process could use this flaw to leak contents of the host memory
bytes.
Upstream patch:
-> https://lists.nongnu.org/archive/html/qemu-devel/2016-11/msg00019.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/12/05/22
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1402247]
---
commit 42a8dadc74f8982fc269e54e3c5627b54d9f83d8
Author: Li Qiang
Date: Tue Nov 1 02:53:11 2016 -0700
virtio-gpu: fix information leak in getting capset info dispatch
Bugzilla
CVE-2016-9846 Qemu: display: virtio-gpu: memory leakage while updating cursor data
bugzilla·2016-12-07·CVSS 6.5
CVE-2016-9846 [MEDIUM] CVE-2016-9846 Qemu: display: virtio-gpu: memory leakage while updating cursor data
CVE-2016-9846 Qemu: display: virtio-gpu: memory leakage while updating cursor data
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is
vulnerable to a memory leakage issue. It could occur while updating the cursor
data in update_cursor_data_virgl.
A guest user/process could use this flaw to leak host memory bytes, resulting
in DoS for a host.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-11/msg00029.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/12/05/23
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1402258]
---
commit 2d1cd6c7a91a4beb99a0c3a21be529222a708545
Author: Li Qiang
Date: Tue Nov 1 04:06:58 2016 -0700
virtio-gpu: fix memory leak in update_cursor_data_virgl
Bugzilla
CVE-2016-9908 Qemu: display: virtio-gpu: information leakage in virgl_cmd_get_capset
bugzilla·2016-12-07·CVSS 3.3
CVE-2016-9908 [LOW] CVE-2016-9908 Qemu: display: virtio-gpu: information leakage in virgl_cmd_get_capset
CVE-2016-9908 Qemu: display: virtio-gpu: information leakage in virgl_cmd_get_capset
Quick Emulator(Qemu) built with the Virtio GPU Device emulator support is
vulnerable to an information leakage issue. It could occur while processing
'VIRTIO_GPU_CMD_GET_CAPSET' command.
A guest user/process could use this flaw to leak contents of the host memory
bytes.
Upstream patch:
-> http://lists.gnu.org/archive/html/qemu-devel/2016-11/msg00059.html
Reference:
-> http://www.openwall.com/lists/oss-security/2016/12/06/2
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1402263]
---
commit 85d9d044471f93c48c5c396f7e217b4ef12f69f8
Author: Li Qiang
Date: Tue Nov 1 05:37:57 2016 -0700
virtio-gpu: fix information leak in capset get dispatch
Bugzilla
CVE-2016-7994 Qemu: virtio-gpu: memory leak in virtio_gpu_resource_create_2d
bugzilla·2016-10-07·CVSS 6.0
CVE-2016-7994 [MEDIUM] CVE-2016-7994 Qemu: virtio-gpu: memory leak in virtio_gpu_resource_create_2d
CVE-2016-7994 Qemu: virtio-gpu: memory leak in virtio_gpu_resource_create_2d
Quick Emulator built with the Virtio GPU Device support is vulnerable to a
memory leakage issue. It could occur while processing virtio GPU command
VIRTIO_GPU_CMD_RESOURCE_CREATE_2D.
A privileged user/process inside guest could use this flaw to exhaust host
memory resulting in DoS.
Upstream fix:
-> https://lists.gnu.org/archive/html/qemu-devel/2016-09/msg04129.html
Discussion:
Acknowledgments:
Name: Li Qiang (360.cn Inc.)
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1382667]
---
commit cb3a0522b694cc5bb6424497b3f828ccd28fd1dd
Author: Li Qiang
Date: Sun Sep 18 19:07:11 2016 -0700
virtio-gpu: fix memory leak in virtio_gpu_resource_create_2d
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securityfocus.com/bid/86453http://www.securitytracker.com/id/1035615http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.securityfocus.com/bid/86453http://www.securitytracker.com/id/1035615
2016-04-21
Published