cbcvebase.

Oracle Http Server vulnerabilities

104 known vulnerabilities affecting oracle/http_server.

Total CVEs
104
CISA KEV
3
actively exploited
Public exploits
11
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH39MEDIUM32LOW6

Vulnerabilities

Page 3 of 6
CVE-2020-35166P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02022-07-11
CVE-2020-35166 [CRITICAL] CWE-385 CVE-2020-35166: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2015-2808P3LOWCVSS 3.7v11.1.1.7.0v11.1.1.9.0+3 more2015-04-01
CVE-2015-2808 [LOW] CWE-327 CVE-2015-2808: The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state dat The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance
nvd
CVE-2020-35168P3CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02022-07-11
CVE-2020-35168 [CRITICAL] CWE-311 CVE-2020-35168: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2018-20843P3HIGHCVSS 7.5v12.1.3.0v12.2.1.4.02019-06-24
CVE-2018-20843 [HIGH] CWE-611 CVE-2018-20843: In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colo In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
nvd
CVE-2022-25314P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02022-02-18
CVE-2022-25314 [HIGH] CWE-190 CVE-2022-25314: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
nvd
CVE-2020-5360P3HIGHCVSS 7.5v11.1.1.9.0v12.1.3.0+1 more2020-12-16
CVE-2020-5360 [HIGH] CWE-127 CVE-2020-5360: Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnera Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.
nvd
CVE-2018-16890P3HIGHCVSS 7.5v12.2.1.3.02019-02-06
CVE-2018-16890 [HIGH] CWE-125 CVE-2018-16890: libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could tr
nvd
CVE-2022-21716P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02022-03-03
CVE-2022-21716 [HIGH] CWE-120 CVE-2022-21716: Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A pat
nvd
CVE-2021-42717P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-12-07
CVE-2021-42717 [HIGH] CWE-674 CVE-2021-42717: ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the a
nvd
CVE-2020-35164P3HIGHCVSS 8.1v12.2.1.3.0v12.2.1.4.02022-07-11
CVE-2020-35164 [HIGH] CWE-385 CVE-2020-35164: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2019-3823P3HIGHCVSS 7.5v12.2.1.3.02019-02-06
CVE-2019-3823 [HIGH] CWE-125 CVE-2019-3823: libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the cod libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read conten
nvd
CVE-2021-4185P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-12-30
CVE-2021-4185 [HIGH] CWE-835 CVE-2021-4185: Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4184P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-12-30
CVE-2021-4184 [HIGH] CWE-835 CVE-2021-4184: Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial o Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4181P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-12-30
CVE-2021-4181 [HIGH] CWE-125 CVE-2021-4181: Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2006-5354P3CRITICALCVSS 10.0v9.2.0.7v10.1.0.52006-10-18
CVE-2006-5354 [CRITICAL] CVE-2006-5354: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10 Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06.
nvd
CVE-2013-6438P3MEDIUMCVSS 5.0v10.1.3.5.0v11.1.1.7.0+2 more2014-03-18
CVE-2013-6438 [MEDIUM] CVE-2013-6438: The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
nvd
CVE-2019-2414P3HIGHCVSS 7.8v12.2.1.3.02019-01-16
CVE-2019-2414 [HIGH] CVE-2019-2414: Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Lis Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerabili
nvd
CVE-1999-1125P3CRITICALCVSS 10.0≤ 2.1v1.01997-09-19
CVE-1999-1125 [CRITICAL] CVE-1999-1125: Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
nvd
CVE-2021-4182P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-12-30
CVE-2021-4182 [HIGH] CWE-835 CVE-2021-4182: Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2006-0435P3HIGHCVSS 7.5v1.0.2.0v1.0.2.1+10 more2006-01-26
CVE-2006-0435 [HIGH] CVE-2006-0435: Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0 Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded pac
nvd
Oracle Http Server vulnerabilities | cvebase