CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2016-0451

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0452.

    Published: 21 Jan 2016
    1.8
    Low

    CVE-2016-0453

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote attackers to affect integrity via unknown vectors related to Embedded Server.

    Published: 21 Jan 2016
    4
    Medium

    CVE-2016-0458

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via vectors related to Kernel DAX.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0460

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.55 allows remote attackers to affect integrity via unknown vectors related to Fluid Homepage and NavBar.

    Published: 21 Jan 2016
    4
    Medium

    CVE-2016-0467

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0476

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0477 and CVE-2016-0478. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0480

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0481, CVE-2016-0482, CVE-2016-0485, and CVE-2016-0486. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the TMAPReportImage parameter.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0481

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0482, CVE-2016-0485, and CVE-2016-0486. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scheduleReportName parameter.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0486

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0485. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the exportFileName parameter.

    Published: 21 Jan 2016
    6.4
    Medium

    CVE-2016-0487

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0490. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the process method in the ActionServlet servlet, which allows remote attackers to bypass authentication via directory traversal sequences following an unspecified URI string.

    Published: 21 Jan 2016
    3.3
    Low

    CVE-2016-0493

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via unknown vectors related to Kernel Cryptography.

    Published: 21 Jan 2016
    6.4
    Medium

    CVE-2016-0514

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0515.

    Published: 21 Jan 2016
    6.4
    Medium

    CVE-2016-0515

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0514.

    Published: 21 Jan 2016
    6.4
    Medium

    CVE-2016-0528

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to User GUI, a different vulnerability than CVE-2016-0527, CVE-2016-0529, and CVE-2016-0530.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0539

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 11.5.10.2, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 21 Jan 2016
    6.4
    Medium

    CVE-2016-0551

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0552, CVE-2016-0559, and CVE-2016-0560.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0555

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CADView-3D component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Studio.

    Published: 21 Jan 2016
    5.5
    Medium

    CVE-2016-0556

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0557.

    Published: 21 Jan 2016
    6.4
    Medium

    CVE-2016-0559

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0551, CVE-2016-0552, and CVE-2016-0560.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0579

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0582, CVE-2016-0583, and CVE-2016-0584.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0586

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to iHelp.

    Published: 21 Jan 2016
    7.8
    High

    CVE-2016-0420

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via unknown vectors related to Monitoring and Diagnostics.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0421

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Monitoring and Diagnostics SEC.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0519

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iReceivables component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AR Web Utilities, a different vulnerability than CVE-2016-0507.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0520

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to Java APIs.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0521

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Redirection.

    Published: 21 Jan 2016
    3.5
    Low

    CVE-2015-4924

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect integrity via vectors related to Security.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0535

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to RPC.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0433

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.9.0 allows remote attackers to affect confidentiality via vectors related to SSL support.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0536

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Universal Work Queue component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to error messages.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0401

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect integrity via unknown vectors related to Scheduler, a different vulnerability than CVE-2016-0429.

    Published: 21 Jan 2016
    7.8
    High

    CVE-2016-0403

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB Utilities.

    Published: 21 Jan 2016
    1.7
    Low

    CVE-2016-0405

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4 allows local users to affect confidentiality via vectors related to Cluster Manageability and Serviceability.

    Published: 21 Jan 2016
    3.3
    Low

    CVE-2016-0406

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via vectors related to Libc.

    Published: 21 Jan 2016
    4
    Medium

    CVE-2016-0409

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Security.

    Published: 21 Jan 2016
    4.6
    Medium

    CVE-2016-0411

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1 and 11.2.0.4 allows local users to affect confidentiality, integrity, and availability via vectors related to Agent Next Gen.

    Published: 21 Jan 2016
    3.5
    Low

    CVE-2016-0412

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise SCM eProcurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Manage Requisition Status.

    Published: 21 Jan 2016
    4
    Medium

    CVE-2016-0413

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Identity Federation component in Oracle Fusion Middleware 11.1.1.7 allows remote authenticated users to affect integrity via vectors related to Federation protocol support.

    Published: 21 Jan 2016
    7.2
    High

    CVE-2016-0414

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0418.

    Published: 21 Jan 2016
    6.1
    Medium

    CVE-2016-0418

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0414.

    Published: 21 Jan 2016
    4.9
    Medium

    CVE-2016-0419

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0431.

    Published: 21 Jan 2016
    7.3
    High

    CVE-2016-0423

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Enterprise Infrastructure SEC.

    Published: 21 Jan 2016
    7.1
    High

    CVE-2016-0424

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect availability via vectors related to Enterprise Infrastructure SEC, a different vulnerability than CVE-2016-0422.

    Published: 21 Jan 2016
    4.9
    Medium

    CVE-2016-0428

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Verified Boot.

    Published: 21 Jan 2016
    4.3
    Medium

    CVE-2016-0429

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect integrity via unknown vectors related to Scheduler, a different vulnerability than CVE-2016-0401.

    Published: 21 Jan 2016
    1.2
    Low

    CVE-2016-0431

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0419.

    Published: 21 Jan 2016
    1.9
    Low

    CVE-2016-0436

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0437, and CVE-2016-0438.

    Published: 21 Jan 2016
    1.9
    Low

    CVE-2016-0437

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0436, and CVE-2016-0438.

    Published: 21 Jan 2016
    1.9
    Low

    CVE-2016-0438

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-2016-0436, and CVE-2016-0437.

    Published: 21 Jan 2016
    5
    Medium

    CVE-2016-0439

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect confidentiality via vectors related to SSL support, a different vulnerability than CVE-2016-0430.

    Published: 21 Jan 2016