CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2016-3421

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to Activity Guide.

    Published: 21 Apr 2016
    8.2
    High

    CVE-2016-3438

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1, and 12.2 allows remote attackers to affect confidentiality and integrity via vectors related to JRAD Heartbeat. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that that this issue involves multiple cross-site scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web script or HTML via three unspecified parameters in an unknown JSP file.

    Published: 21 Apr 2016
    8.2
    High

    CVE-2016-3439

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Wireless component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Call Phone Number Page.

    Published: 21 Apr 2016
    4.6
    Medium

    CVE-2016-3457

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM ePerformance component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-3463

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login.

    Published: 21 Apr 2016
    6.5
    Medium

    CVE-2016-0407

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusion HR Talent Integration.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0408

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 through 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to the Activity Guide sub-component.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0468

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-0672

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login.

    Published: 21 Apr 2016
    6.7
    Medium

    CVE-2016-0678

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.18 allows local users to affect confidentiality, integrity, and availability via vectors related to Core.

    Published: 21 Apr 2016
    8.7
    High

    CVE-2016-0679

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect integrity and availability via vectors related to PIA Grids.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0683

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Search Framework.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-0693

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the PAM LDAP module.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0698

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Rich Text Editor, a different vulnerability than CVE-2016-3423.

    Published: 21 Apr 2016
    9
    Critical

    CVE-2016-3454

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 21 Apr 2016
    8.2
    High

    CVE-2016-3456

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul component in Oracle Supply Chain Products Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Dialog Box.

    Published: 21 Apr 2016
    5.7
    Medium

    CVE-2016-3464

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-0623

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect integrity via vectors related to the Automated Installer sub-component.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0469

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-0479

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality and integrity via vectors related to Analytics Scorecard.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-0638

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.

    Published: 21 Apr 2016
    6
    Medium

    CVE-2016-0669

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Fwflash.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0673

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to UIF Open UI.

    Published: 21 Apr 2016
    4.4
    Medium

    CVE-2016-0674

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality and integrity via vectors related to Email.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-0675

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-0676

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to the kernel.

    Published: 21 Apr 2016
    5.9
    Medium

    CVE-2016-0677

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0680

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise SCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Services Procurement.

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-0681

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unspecified vectors.

    Published: 21 Apr 2016
    6.5
    Medium

    CVE-2016-0684

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail MICROS ARS POS component in Oracle Retail Applications 1.5 allows remote authenticated users to affect confidentiality via vectors related to POS.

    Published: 21 Apr 2016
    3.7
    Low

    CVE-2016-0688

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to Core Components.

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-0689

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0692, CVE-2016-0694, and CVE-2016-3418.

    Published: 21 Apr 2016
    3.3
    Low

    CVE-2016-0690

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0691.

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-0694

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0689, CVE-2016-0692, and CVE-2016-3418.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0696

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 allows remote attackers to affect confidentiality and integrity via vectors related to Console.

    Published: 21 Apr 2016
    9.1
    Critical

    CVE-2016-0699

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-0700

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675.

    Published: 21 Apr 2016
    7.5
    High

    CVE-2016-1362

    Last Modified: 12 Apr 2025

    Cisco AireOS 4.1 through 7.4.120.0, 7.5.x, and 7.6.100.0 on Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device reload) via a crafted HTTP request, aka Bug ID CSCun86747.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-1363

    Last Modified: 12 Apr 2025

    Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCus25617.

    Published: 21 Apr 2016
    7.5
    High

    CVE-2016-1367

    Last Modified: 12 Apr 2025

    The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID CSCus23248.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-2005

    Last Modified: 12 Apr 2025

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3352.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-2006

    Last Modified: 12 Apr 2025

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3353.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-2007

    Last Modified: 12 Apr 2025

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3354.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-2008

    Last Modified: 12 Apr 2025

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 21 Apr 2016
    7.5
    High

    CVE-2016-2280

    Last Modified: 12 Apr 2025

    Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.

    Published: 21 Apr 2016
    8.6
    High

    CVE-2016-2293

    Last Modified: 12 Apr 2025

    The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover settings via a direct request to an unspecified URL.

    Published: 21 Apr 2016
    7.5
    High

    CVE-2016-2294

    Last Modified: 12 Apr 2025

    The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover a cleartext mail-server password via unspecified vectors.

    Published: 21 Apr 2016
    3.3
    Low

    CVE-2016-3419

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via vectors related to Filesystem.

    Published: 21 Apr 2016
    3.1
    Low

    CVE-2016-3428

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface.

    Published: 21 Apr 2016
    6.4
    Medium

    CVE-2016-3431

    Last Modified: 8 May 2025

    Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3420.

    Published: 21 Apr 2016