cbcvebase.

Oracle Linux vulnerabilities

228 known vulnerabilities affecting oracle/linux.

Total CVEs
228
CISA KEV
7
actively exploited
Public exploits
14
Exploited in wild
9
Severity breakdown
CRITICAL24HIGH84MEDIUM101LOW19

Vulnerabilities

Page 11 of 12
CVE-2016-4581P4MEDIUMCVSS 5.5v62016-05-23
CVE-2016-4581 [MEDIUM] CVE-2016-4581: fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount system calls.
nvd
CVE-2014-0203P4MEDIUMCVSS 5.5v5v62014-06-23
CVE-2014-0203 [MEDIUM] CWE-416 CVE-2014-0203: The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly hand The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
nvd
CVE-2015-6246P4MEDIUMCVSS 4.3v72015-08-24
CVE-2015-6246 [MEDIUM] CWE-20 CVE-2015-6246: The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2016-1958P4MEDIUMCVSS 4.3v5.0v6+1 more2016-03-13
CVE-2016-1958 [MEDIUM] CWE-254 CVE-2016-1958: browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allo browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
nvd
CVE-2016-0606P4LOWCVSS 3.5v72016-01-21
CVE-2016-0606 [LOW] CVE-2016-0606: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
nvd
CVE-2015-4913P4LOWCVSS 3.5v72015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2015-2922P4LOWCVSS 3.3v5.02015-05-27
CVE-2015-2922 [LOW] CWE-17 CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol impl The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
nvd
CVE-2026-35233P4MEDIUMCVSS 4.4v8v9+1 more2026-05-01
CVE-2026-35233 [MEDIUM] CWE-125 CVE-2026-35233: An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an ou An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in a
nvd
CVE-2016-7166P4MEDIUMCVSS 5.5v6v72016-09-21
CVE-2016-7166 [MEDIUM] CWE-399 CVE-2016-7166: libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote a libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
nvd
CVE-2014-3144P4MEDIUMCVSS 4.9v6v72014-05-11
CVE-2014-3144 [MEDIUM] CWE-190 CVE-2014-3144: The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filte The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows local users to cause a denial of service (integer underflow and system crash) via crafted BPF instructions
nvd
CVE-2016-0598P4LOWCVSS 3.5v72016-01-21
CVE-2016-0598 [LOW] CVE-2016-0598: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-0608P4LOWCVSS 3.5v72016-01-21
CVE-2016-0608 [LOW] CVE-2016-0608: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF.
nvd
CVE-2016-0600P4LOWCVSS 3.5v72016-01-21
CVE-2016-0600 [LOW] CVE-2016-0600: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2016-0609P4LOWCVSS 1.7v72016-01-21
CVE-2016-0609 [LOW] CVE-2016-0609: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.
nvd
CVE-2016-0617P4MEDIUMCVSS 5.5v6.02016-09-30
CVE-2016-0617 [MEDIUM] CVE-2016-0617: Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via unknown vectors.
nvd
CVE-2016-1957P4MEDIUMCVSS 4.3v5.0v6+1 more2016-03-13
CVE-2016-1957 [MEDIUM] CWE-119 CVE-2016-1957: Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
nvd
CVE-2014-3145P4MEDIUMCVSS 4.9v6v72014-05-11
CVE-2014-3145 [MEDIUM] CWE-125 CVE-2014-3145: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter. The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nla
nvd
CVE-2015-4861P4LOWCVSS 3.5v72015-10-21
CVE-2015-4861 [LOW] CVE-2015-4861: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2015-4792P4LOWCVSS 1.7v72015-10-21
CVE-2015-4792 [LOW] CVE-2015-4792: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.
nvd
CVE-2015-0275P4MEDIUMCVSS 4.9v72015-10-19
CVE-2015-0275 [MEDIUM] CWE-17 CVE-2015-0275: The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users to cause a denial of service (BUG) via a crafted fallocate zero-range request.
nvd
Oracle Linux vulnerabilities | cvebase