CVE-2016-3545
published 2016-07-21CVE-2016-3545: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote…
PriorityP429medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.31%
81.3th percentile
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via vectors related to Web based help screens.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_object_library | — | — |
| oracle | application_object_library | — | — |
| oracle | application_object_library | — | — |
| oracle | application_object_library | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8grq-p3rh-q3cg: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12
ghsa_unreviewed·2022-05-17
CVE-2016-3545 [MEDIUM] GHSA-8grq-p3rh-q3cg: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via vectors related to Web based help screens.
Red Hat
Mozilla: Use-after-free in HTML5 string parser (MFSA 2016-23)
vendor_redhat·2016-03-08·CVSS 8.8
CVE-2016-1960 [HIGH] Mozilla: Use-after-free in HTML5 string parser (MFSA 2016-23)
Mozilla: Use-after-free in HTML5 string parser (MFSA 2016-23)
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securityfocus.com/bid/91882http://www.securitytracker.com/id/1036403http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securityfocus.com/bid/91882http://www.securitytracker.com/id/1036403
2016-07-21
Published