cbcvebase.

Oracle Http Server vulnerabilities

104 known vulnerabilities affecting oracle/http_server.

Total CVEs
104
CISA KEV
3
actively exploited
Public exploits
11
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH39MEDIUM32LOW6

Vulnerabilities

Page 4 of 6
CVE-2020-26184P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02022-06-01
CVE-2020-26184 [HIGH] CWE-295 CVE-2020-26184: Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
nvd
CVE-2022-21593P3HIGHCVSS 7.1v12.2.1.3.0v12.2.1.4.02022-10-18
CVE-2022-21593 [HIGH] CVE-2022-21593: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config M Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a perso
nvd
CVE-2021-25219P3MEDIUMCVSS 5.3v12.2.1.3.0v12.2.1.4.02021-10-27
CVE-2021-25219 [MEDIUM] CVE-2021-25219: In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9. In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance.
nvd
CVE-2014-0098P3MEDIUMCVSS 5.0v10.1.3.5.0v11.1.1.7.0+2 more2014-03-18
CVE-2014-0098 [MEDIUM] CVE-2014-0098: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server b The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
nvd
CVE-2021-41617P3HIGHCVSS 7.0v12.2.1.2.0v12.2.1.3.0+1 more2021-09-26
CVE-2021-41617 [HIGH] CVE-2021-41617: sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration spec
nvd
CVE-2020-26185P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02022-06-01
CVE-2020-26185 [HIGH] CWE-20 CVE-2020-26185: Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
nvd
CVE-2020-2952P3MEDIUMCVSS 6.5v11.1.1.9.02020-04-15
CVE-2020-2952 [MEDIUM] CVE-2020-2952: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized update,
nvd
CVE-2018-2760P3MEDIUMCVSS 5.9v12.1.3v12.2.1.22018-04-19
CVE-2018-2760 [MEDIUM] CVE-2018-2760: Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OSSL Mo Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OSSL Module). Supported versions that are affected are 12.1.3 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2019-2751P3MEDIUMCVSS 5.9v12.1.3.0.0v12.2.1.3.02019-07-23
CVE-2019-2751 [MEDIUM] CVE-2019-2751: Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Con Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can resu
nvd
CVE-2020-1971P3MEDIUMCVSS 5.9v12.2.1.4.02020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd
CVE-2019-5443P3HIGHCVSS 7.8v12.2.1.3.0v12.2.1.4.02019-07-02
CVE-2019-5443 [HIGH] CWE-94 CVE-2019-5443: A non-privileged user or program can put code and a config file in a known non-privileged path (unde A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.
nvd
CVE-2007-5000P4MEDIUMCVSS 4.3v10.1.3.5.02007-12-13
CVE-2007-5000 [MEDIUM] CWE-79 CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2021-43818P3HIGHCVSS 7.1v12.2.1.3.0v12.2.1.4.02021-12-13
CVE-2021-43818 [HIGH] CWE-74 CVE-2021-43818: lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HT lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch.
nvd
CVE-2020-24977P4MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.02020-09-04
CVE-2020-24977 [MEDIUM] CWE-125 CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesIntern GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
nvd
CVE-2022-25313P4MEDIUMCVSS 6.5v12.2.1.3.0v12.2.1.4.02022-02-18
CVE-2022-25313 [MEDIUM] CWE-674 CVE-2022-25313: In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
nvd
CVE-2006-5348P4CRITICALCVSS 10.0v9.2.0.72006-10-18
CVE-2006-5348 [CRITICAL] CVE-2006-5348: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Ora Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.
nvd
CVE-2006-5349P4CRITICALCVSS 10.0v9.2.0.72006-10-18
CVE-2006-5349 [CRITICAL] CVE-2006-5349: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS07.
nvd
CVE-2021-35666P3MEDIUMCVSS 5.9v11.1.1.9.02021-10-20
CVE-2021-35666 [MEDIUM] CVE-2021-35666: Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module) Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized acce
nvd
CVE-2006-5347P4CRITICALCVSS 10.0v9.2.0.72006-10-18
CVE-2006-5347 [CRITICAL] CVE-2006-5347: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle Collaboration Suite 9.0.4.2 has u Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle Collaboration Suite 9.0.4.2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS04.
nvd
CVE-2007-0280P4HIGHCVSS 7.5v9.0.1.52007-01-17
CVE-2007-0280 [HIGH] CVE-2007-0280: Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10. Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OP
nvd
Oracle Http Server vulnerabilities | cvebase