CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically within the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in the Parser Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Parser component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Thread Pooling Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Server: Thread Pooling component. This vulnerability affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The issue is easily exploitable, allowing an unauthenticated attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in Oracle MySQL Server in versions through 8.0.40, 8.4.3 and 9.1.0. This difficult-to-exploit vulnerability allows a high-privileged attacker with access to the MySQL Server environment to compromise the server. Exploitation requires human interaction from a third party. Successful attacks could lead to unauthorized read access to certain data within MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Privileges Component
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the Privileges component of the Security feature. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with network access through multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a low-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server, leading to a complete denial-of-service condition.
Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Data Modification
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized update, insert, or delete access to some data within JD Edwards EnterpriseOne Tools.
Oracle E-Business Suite Customer Care Service Requests Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Customer Care component of Oracle E-Business Suite, specifically in versions 12.2.5 through 12.2.13. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible within Oracle Customer Care.
Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Takeover
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized takeover of the application.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Exposure Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete certain data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, it may significantly impact additional products. Exploitation of this vulnerability could lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data, as well as unauthorized update, insert, or delete access to other accessible data.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the JD Edwards EnterpriseOne Tools product, specifically within the Web Runtime SEC component. This issue affects versions prior to 9.2.9.0. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to disrupt JD Edwards EnterpriseOne Tools. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the application.
Oracle JD Edwards Web Runtime SEC Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the JD Edwards EnterpriseOne Tools product, specifically within the Web Runtime SEC component. This issue affects versions prior to 9.2.9.0. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to disrupt JD Edwards EnterpriseOne Tools. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the application.
Oracle JD Edwards Web Runtime SEC Vulnerability in EnterpriseOne Tools Allowing Data Access and Modification
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically within the Web Runtime SEC component. This issue affects versions prior to 9.2.9.0. The vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Exploitation of this vulnerability requires human interaction from someone other than the attacker. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, successful attacks could significantly impact additional products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain subsets of JD Edwards EnterpriseOne Tools data, as well as unauthorized update, insert, or delete access to other accessible data within the same tools.
Oracle E-Business Suite Project Foundation Technology Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Project Foundation component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.13. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all data accessible within Oracle Project Foundation.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability allows a high-privileged attacker with network access to MySQL Server, through multiple protocols, to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server, leading to a complete denial-of-service condition.
Oracle MySQL InnoDB Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. This vulnerability affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. It allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle Java SE and GraalVM Vulnerability Allowing Unauthorized Data Access
A vulnerability has been identified in multiple versions of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. This vulnerability, which affects the Hotspot component, allows an unauthenticated attacker with network access to compromise the Java runtime. Successful exploitation can lead to unauthorized read access and the ability to update, insert, or delete certain accessible data. The vulnerability can be exploited through APIs, potentially via a web service, and also impacts Java deployments that run untrusted code from the internet, relying on the Java sandbox for security.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a low-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions through 8.4.3 and 9.1.0. This vulnerability allows a high-privileged attacker with network access to MySQL Server, via multiple protocols, to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle HTTP Server Core Component Vulnerability in Oracle Fusion Middleware
A vulnerability has been identified in the Oracle HTTP Server component of Oracle Fusion Middleware, specifically in version 12.2.1.4.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the server. Successful exploitation can lead to unauthorized read access to certain data accessible through Oracle HTTP Server.
Oracle MySQL InnoDB Component Denial-of-Service and Data Manipulation Vulnerability
A vulnerability exists in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. Affected versions include 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability is easily exploitable and allows a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause a hang or a frequently repeatable crash, resulting in a complete denial-of-service for the MySQL Server. Additionally, it allows unauthorized update, insert, or delete access to some data accessible by the MySQL Server.
Oracle MySQL Enterprise Firewall Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Enterprise Firewall component of Oracle MySQL. This issue affects versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with network access via multiple protocols to disrupt MySQL Enterprise Firewall. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the firewall component.
Oracle MySQL Server Denial-of-Service Vulnerability in Privileges Component
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the Privileges component of the Security feature. This issue affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with access to the MySQL Server environment to cause a complete server hang or a frequently repeatable crash, leading to a total denial-of-service condition.
Oracle MySQL Server Privilege Vulnerability Leading to Denial-of-Service
A vulnerability exists in Oracle MySQL Server in versions 8.4.3 and prior, as well as 9.1.0 and prior. This vulnerability, which is difficult to exploit, allows a high-privileged attacker with network access through multiple protocols to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the optimizer component. This issue affects MySQL Server versions through 8.0.36 and through 8.4.0. The vulnerability allows a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Exploitation of this vulnerability can lead to unauthorized actions causing the MySQL Server to hang or crash repeatedly, resulting in a complete denial-of-service.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically within the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the InnoDB component of Oracle MySQL Server. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a complete server hang or a frequently repeatable crash, leading to a total denial-of-service condition.
Oracle E-Business Suite Advanced Outbound Telephony Region Mapping Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite, specifically in versions 12.2.3 through 12.2.10. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Exploitation of this vulnerability requires human interaction from a third party. While the vulnerability is contained within Oracle Advanced Outbound Telephony, successful attacks could significantly affect other products, leading to a scope change. The vulnerability allows for unauthorized read access to certain subsets of Oracle Advanced Outbound Telephony data, as well as unauthorized update, insert, or delete access to some accessible data within the application.
Linksys E8450 Buffer Overflow Vulnerability in DHCP Field Parsing
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field 'hidden_dhcp_num' is copied to the stack without proper length verification, creating the potential for memory corruption.
Linksys E8450 Buffer Overflow Vulnerability in LAN IP Address Parsing
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field 'lan_ipaddr' is copied to the stack without proper length verification, creating the potential for memory corruption.
Linksys E8450 Buffer Overflow Vulnerability in DHCP Start IP Parsing
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises in the JSON parsing function 'sub_422eb8', where the 'dhcpstart_ip' field is copied to the stack using 'strcpy' without proper length validation. This lack of verification creates an opportunity for a buffer overflow, potentially allowing for arbitrary code execution or causing the device to crash.
Linksys E8450 Command Injection Vulnerability
A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the 'id_email_check_btn' field, where user-supplied input is improperly sanitized before being passed to the system function, allowing for arbitrary command execution.
Linksys E8450 Buffer Overflow Vulnerability in IPv6 Protection Status Field
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the IPv6 protection status field is copied to the stack without proper length verification, allowing for potential memory corruption.
Linksys E8450 Buffer Overflow Vulnerability
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The vulnerability arises because the parsed action field is copied to the stack without proper length verification, allowing for potential memory corruption.
Linksys E8450 Command Injection Vulnerability in Email Registration
A command injection vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the JSON parsing function of the device's portal CGI script, where the 'userEmail' field can be manipulated to execute arbitrary commands on the system.
Linksys E8450 Buffer Overflow Vulnerability in Dashboard Configuration Security
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in firmware version 1.2.00.360516. The issue arises in the JSON parsing function 'sub_422eb8', where the 'anonymous_protect_status' field is copied to the stack using 'strncpy' without proper length validation. This flaw can be exploited by sending crafted data to the 'portal.cgi' URL, causing the device to crash.
Linksys E8450 Buffer Overflow Vulnerability
A buffer overflow vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The issue arises because the parsed field (page) is copied to the stack without proper length verification, allowing for potential memory corruption.
Linksys E8450 Command Injection Vulnerability
A command injection vulnerability has been identified in the Linksys E8450 router, specifically in version 1.2.00.360516. The vulnerability arises in the 'wizard_status' component, allowing attackers to inject and execute arbitrary commands on the device.
GNU Binutils Incorrect Access Control Vulnerability in 'nm' Command
A vulnerability has been identified in GNU Binutils 'nm' command versions 2.43 and later, related to incorrect access control. This vulnerability allows for local exploitation, specifically within the 'nm --without-symbol-version' function.
Northern.tech Mender Client Insecure Permissions Vulnerability in Private Key File
A vulnerability exists in Northern.tech Mender Client versions 4.0.0 through 4.0.4, where private key files generated on devices may be improperly accessible to other users due to lax file permissions. This issue arises because the Mender authentication process creates a private key file with read permissions for other users, and these permissions are not corrected, potentially allowing unauthorized access to the key.
Northern.tech CFEngine Enterprise Mission Portal Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Northern.tech CFEngine Enterprise Mission Portal versions 3.24.0, 3.21.5, and earlier. The issue arises from missing input validation, allowing authenticated users with administrator privileges to inject JavaScript into text fields. This injected script could be executed by other users who access the same form. While the vulnerability is limited to the settings area and requires specific actions to exploit, it could facilitate XSS between two administrator accounts.
OrangeScrum Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in OrangeScrum version 2.0.11. This issue allows attackers to inject malicious JavaScript into user email fields, exploiting inadequate input validation. The consequence of this vulnerability could be account takeover.
Oracle JD Edwards EnterpriseOne Tools Business Logic Infra SEC Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, specifically in the Business Logic Infra SEC component, affecting versions prior to 9.2.9.0. This vulnerability allows low-privileged attackers with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, successful attacks could significantly impact additional products. The vulnerability could lead to unauthorized updates, inserts, or deletions of accessible data within JD Edwards EnterpriseOne Tools, as well as unauthorized read access to certain subsets of that data.
Mjolnir Moderation Tool for Matrix Command Execution Vulnerability
A vulnerability in the Mjolnir moderation tool for Matrix, specifically in version 1.9.0, allows the bot to respond to management commands from any room it is a member of. This issue can enable users who are not bot operators to access the bot's functions, including server administration components if activated. The vulnerability arises from a feature that improperly manages command responses based on room membership.
