cbcvebase.

Oracle Linux vulnerabilities

228 known vulnerabilities affecting oracle/linux.

Total CVEs
228
CISA KEV
7
actively exploited
Public exploits
14
Exploited in wild
9
Severity breakdown
CRITICAL24HIGH84MEDIUM101LOW19

Vulnerabilities

Page 2 of 12
CVE-2016-2182P3CRITICALCVSS 9.8v5v6+1 more2016-09-16
CVE-2016-2182 [CRITICAL] CWE-787 CVE-2016-2182: The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate di The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-1908P2CRITICALCVSS 9.8v6v72017-04-11
CVE-2016-1908 [CRITICAL] CWE-287 CVE-2016-1908: The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding an The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as demonstrated by lack of the SEC
nvd
CVE-2015-3329P3HIGHCVSS 7.5v6v72015-06-09
CVE-2015-3329 [HIGH] CWE-119 CVE-2015-3329: Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP befor Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.
nvd
CVE-2016-4051P3HIGHCVSS 8.8v6v72016-04-25
CVE-2016-4051 [HIGH] CWE-119 CVE-2016-4051: Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow re Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
nvd
CVE-2016-0777P3MEDIUMCVSS 6.5v72016-01-14
CVE-2016-0777 [MEDIUM] CWE-200 CVE-2016-0777: The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
nvd
CVE-2015-4643P3CRITICALCVSS 9.8v6v72016-05-16
CVE-2015-4643 [CRITICAL] CVE-2015-4643: Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5 Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4022.
nvd
CVE-2015-4870P3MEDIUMCVSS 4.0PoCv72015-10-21
CVE-2015-4870 [MEDIUM] CVE-2015-4870: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
nvd
CVE-2015-8668P3CRITICALCVSS 9.8v6v72016-01-08
CVE-2015-8668 [CRITICAL] CWE-787 CVE-2015-8668: Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtif Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a large width field in a BMP image.
nvd
CVE-2016-4555P3HIGHCVSS 7.5v6v72016-05-10
CVE-2016-4555 [HIGH] CWE-20 CVE-2016-4555: client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cau client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
nvd
CVE-2016-0778P3HIGHCVSS 8.1v72016-01-14
CVE-2016-0778 [HIGH] CWE-119 CVE-2016-0778: The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5. The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified othe
nvd
CVE-2016-5408P3CRITICALCVSS 9.8v62016-08-10
CVE-2016-5408 [CRITICAL] CVE-2016-5408: Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package be Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.
nvd
CVE-2016-3598P3CRITICALCVSS 9.6v5.0v6+1 more2016-07-21
CVE-2016-3598 [CRITICAL] CVE-2016-3598: Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers t Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3610.
nvd
CVE-2013-5704P3MEDIUMCVSS 5.0v62014-04-15
CVE-2013-5704 [MEDIUM] CVE-2013-5704: The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHe The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
nvd
CVE-2016-4998P3HIGHCVSS 7.1PoCv72016-07-03
CVE-2016-4998 [HIGH] CWE-119 CVE-2016-4998: The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel befo The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob bou
nvd
CVE-2015-7512P3CRITICALCVSS 9.0v62016-01-08
CVE-2015-7512 [CRITICAL] CWE-120 CVE-2015-7512: Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larg Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
nvd
CVE-2016-3587P3CRITICALCVSS 9.6v6v72016-07-21
CVE-2016-3587 [CRITICAL] CVE-2016-3587: Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers t Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.
nvd
CVE-2016-3610P3CRITICALCVSS 9.6v5.0v6+1 more2016-07-21
CVE-2016-3610 [CRITICAL] CVE-2016-3610: Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers t Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3598.
nvd
CVE-2004-2771P3HIGHCVSS 7.5v6v72014-12-24
CVE-2004-2771 [HIGH] CWE-20 CVE-2004-2771: The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allo The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
nvd
CVE-2015-5165P3CRITICALCVSS 9.3v72015-08-12
CVE-2015-5165 [CRITICAL] CWE-908 CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
nvd
CVE-2016-3606P3CRITICALCVSS 9.6v5.0v6.0+1 more2016-07-21
CVE-2016-3606 [CRITICAL] CVE-2016-3606: Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote a Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.
nvd
Oracle Linux vulnerabilities | cvebase