CVE-2016-5482
published 2016-10-25CVE-2016-5482: Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote…
PriorityP339high8.2CVSS 3.0
AVNACLPRNUIRSCCHILAN
EPSS
1.43%
69.8th percentile
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | commerce_guided_search | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | commerce_guided_search | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3mf-jf72-hcpp: Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6
ghsa_unreviewed·2022-05-17
CVE-2016-5482 [HIGH] CWE-284 GHSA-m3mf-jf72-hcpp: Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
Red Hat
tcpdump: multiple overflow issues in protocol decoding
vendor_redhat·2017-02-02·CVSS 9.8
CVE-2016-8575 [CRITICAL] CWE-125 tcpdump: multiple overflow issues in protocol decoding
tcpdump: multiple overflow issues in protocol decoding
The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482.
Multiple out of bounds read and integer overflow vulnerabilities were found in tcpdump affecting the decoding of various protocols. An attacker could create a crafted pcap file or send specially crafted packets to the network segment where tcpdump is running in live capture mode (without -w) which could cause it to display incorrect data, crash or enter an infinite loop.
Statement: Red Hat Product Security has rated these issues as having Moderate security impact. These issues may be fixed in a future minor release of Red Hat Enterprise Linux 7. For additional information, refer to the Issue Severi
Red Hat
tcpdump: multiple overflow issues in protocol decoding
vendor_redhat·2017-02-02·CVSS 9.8
CVE-2017-5482 [CRITICAL] CWE-125 tcpdump: multiple overflow issues in protocol decoding
tcpdump: multiple overflow issues in protocol decoding
The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.
Multiple out of bounds read and integer overflow vulnerabilities were found in tcpdump affecting the decoding of various protocols. An attacker could create a crafted pcap file or send specially crafted packets to the network segment where tcpdump is running in live capture mode (without -w) which could cause it to display incorrect data, crash or enter an infinite loop.
Statement: Red Hat Product Security has rated these issues as having Moderate security impact. These issues may be fixed in a future minor release of Red Hat Enterprise Linux 7. For additional information, refer to the Issue Severi
No detection rules found.
No public exploits indexed.
2016-10-25
Published