Oracle Secure Global Desktop vulnerabilities
33 known vulnerabilities affecting oracle/secure_global_desktop.
Total CVEs
33
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
4
Severity breakdown
CRITICAL11HIGH5MEDIUM17
Vulnerabilities
Page 2 of 2
CVE-2016-5580P3CRITICALCVSS 9.6v4.7v5.22016-10-25
CVE-2016-5580 [CRITICAL] CWE-284 CVE-2016-5580: Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.
Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services.
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9v5.3v5.42018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9v5.42019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2018-16890P3HIGHCVSS 7.5v5.42019-02-06
CVE-2018-16890 [HIGH] CWE-125 CVE-2018-16890: libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could tr
nvd
CVE-2019-3823P3HIGHCVSS 7.5v5.42019-02-06
CVE-2019-3823 [HIGH] CWE-125 CVE-2019-3823: libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the cod
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read conten
nvd
CVE-2014-0098P3MEDIUMCVSS 5.0v4.63v4.71+2 more2014-03-18
CVE-2014-0098 [MEDIUM] CVE-2014-0098: The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server b
The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1v5.4v5.52018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-0735P4MEDIUMCVSS 5.9v5.42018-10-29
CVE-2018-0735 [MEDIUM] CWE-327 CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attac
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
nvd
CVE-2013-2064P4MEDIUMCVSS 6.8v4.71v5.22013-06-15
CVE-2013-2064 [MEDIUM] CWE-189 CVE-2013-2064: Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insuffici
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
nvd
CVE-2019-17091P4MEDIUMCVSS 6.1v5.4v5.52019-10-02
CVE-2019-17091 [MEDIUM] CWE-79 CVE-2019-17091: faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J be
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
nvd
CVE-2021-35649P4MEDIUMCVSS 5.4v5.62021-10-20
CVE-2021-35649 [MEDIUM] CVE-2021-35649: Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Serve
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. Successful attacks of this vulnerability can result in un
nvd
CVE-2016-0501P4MEDIUMCVSS 5.0v5.22016-01-21
CVE-2016-0501 [MEDIUM] CVE-2016-0501: Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.2
Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.2 allows remote attackers to affect availability via vectors related to SGD Core.
nvd
CVE-2021-35650P4MEDIUMCVSS 4.6v5.62021-10-20
CVE-2021-35650 [MEDIUM] CVE-2021-35650: Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Clien
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. Successful attacks require human interaction from a perso
nvd
← Previous2 / 2