Oracle Enterprise Communications Broker vulnerabilities

28 known vulnerabilities affecting oracle/enterprise_communications_broker.

Total CVEs
28
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM12LOW1

Vulnerabilities

Page 2 of 2
CVE-2018-16864HIGHCVSS 7.8v3.0.0v3.1.02019-01-11
CVE-2018-16864 [HIGH] CWE-770 CVE-2018-16864: An allocation of memory without limits, that could result in the stack clashing with another memory An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
nvd
CVE-2018-11236CRITICALCVSS 9.8v3.0.0v3.1.02018-05-18
CVE-2018-11236 [CRITICAL] CWE-190 CVE-2018-11236: stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing ve stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
nvd
CVE-2018-11237HIGHCVSS 7.8v3.0.0v3.1.02018-05-18
CVE-2018-11237 [HIGH] CWE-787 CVE-2018-11237: An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6 An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
nvd
CVE-2018-6485CRITICALCVSS 9.8v3.0.0v3.1.02018-02-01
CVE-2018-6485 [CRITICAL] CWE-190 CVE-2018-6485: An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C L An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
nvd
CVE-2016-3515HIGHCVSS 7.5≤ 2.0.0412016-07-21
CVE-2016-3515 [HIGH] CVE-2016-3515: Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communi Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2016-3514MEDIUMCVSS 6.5≤ 2.0.0412016-07-21
CVE-2016-3514 [MEDIUM] CVE-2016-3514: Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communi Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerability than CVE-2016-3516.
nvd
CVE-2016-3516LOWCVSS 3.1≤ 2.0.0412016-07-21
CVE-2016-3516 [LOW] CVE-2016-3516: Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communi Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerability than CVE-2016-3514.
nvd
CVE-2014-9708MEDIUMCVSS 5.0≤ 2.0.02015-03-31
CVE-2014-9708 [MEDIUM] CWE-476 CVE-2014-9708: Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of serv Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
nvd