CVE-2017-10199
published 2017-08-08CVE-2017-10199: Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). The supported version that is affected is 6.2. Easily…
PriorityP342high8.2CVSS 3.0
AVNACLPRNUIRSCCHILAN
EPSS
1.93%
77.6th percentile
Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). The supported version that is affected is 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iLearning, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iLearning accessible data as well as unauthorized update, insert or delete access to some of Oracle iLearning accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | ilearning | — | — |
| oracle_corporation | ilearning | — | — |
CVSS provenance
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10199 gstreamer-plugins-good: Out of bounds read in qtdemux_tag_add_str_full
bugzilla·2017-02-06·CVSS 7.5
CVE-2016-10199 [HIGH] CVE-2016-10199 gstreamer-plugins-good: Out of bounds read in qtdemux_tag_add_str_full
CVE-2016-10199 gstreamer-plugins-good: Out of bounds read in qtdemux_tag_add_str_full
An out-of-bounds read in qtdemux_tag_add_str_full was found that can be triggered by specially crafted file.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=775451
Upstream patch:
https://github.com/GStreamer/gst-plugins-good/commit/d0949baf3dadea6021d54abef6802fed5a06af75
CVE assignment:
http://seclists.org/oss-sec/2017/q1/284
Discussion:
Created mingw-gstreamer1-plugins-good tracking bugs for this issue:
Affects: fedora-all [bug 1419611]
---
Created mingw-gstreamer-plugins-good tracking bugs for this issue:
Affects: fedora-all [bug 1419610]
---
Created gstreamer-plugins-good tracking bugs for this issue:
Affects: fedora-all [bug 1419608]
---
Created gstreamer1-plugins-good tra
Bugzilla
CVE-2016-10199 CVE-2017-5840 CVE-2017-5841 CVE-2017-5845 gstreamer-plugins-good: various flaws [fedora-all]
bugzilla·2017-02-06·CVSS 7.5
CVE-2016-10199 [HIGH] CVE-2016-10199 CVE-2017-5840 CVE-2017-5841 CVE-2017-5845 gstreamer-plugins-good: various flaws [fedora-all]
CVE-2016-10199 CVE-2017-5840 CVE-2017-5841 CVE-2017-5845 gstreamer-plugins-good: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/99637http://www.securitytracker.com/id/1038949http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/99637http://www.securitytracker.com/id/1038949
2017-08-08
Published