Oracle / Communications Application Session Controller
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2021-29425 | Possible limited path traversal vulnerabily in Apache Commons IO | MEDIUM | 4.8 | Apr 13, 2021 |
| CVE-2020-11987 | batik: SSRF due to improper input validation by the NodePickerPanel | HIGH | 8.2 | Feb 24, 2021 |
| CVE-2020-28052 | bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible | HIGH | 8.1 | Dec 18, 2020 |
| CVE-2019-17566 | batik: SSRF via "xlink:href" | HIGH | 7.5 | Nov 12, 2020 |
| CVE-2020-27216 | jetty: local temporary directory hijacking vulnerability | HIGH | 7.0 | Oct 23, 2020 |
| CVE-2020-10683 | dom4j: XML External Entity vulnerability in default SAX parser | CRITICAL | 9.8 | May 1, 2020 |
| CVE-2020-11022 | jQuery has a potential XSS vulnerability | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-9488 | log4j: improper validation of certificate with host mismatch in SMTP appender | LOW | 3.7 | Apr 27, 2020 |
| CVE-2020-5258 | Prototype pollution in dojo | HIGH | 7.7 | Mar 10, 2020 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 6.1 | Nov 8, 2019 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
| CVE-2018-11784 | tomcat: Open redirect in default servlet | MEDIUM | 5.3 | Oct 4, 2018 |
| CVE-2018-1000613 | bouncycastle: lack of class checking in deserialization of XMSS/XMSS^MT private keys with BDS state information | CRITICAL | 9.8 | Jul 9, 2018 |
| CVE-2018-1000180 | bouncycastle: flaw in the low-level interface to RSA key pair generator | HIGH | 7.5 | Jun 5, 2018 |
| CVE-2017-3730 | Bad (EC)DHE parameters cause a client crash | HIGH | 7.5 | May 4, 2017 |
| CVE-2016-8735 KEV | tomcat: Remote code execution vulnerability in JmxRemoteLifecycleListener | CRITICAL | 9.8 | Apr 6, 2017 |
| CVE-2015-2808 | SSL/TLS: "Invariance Weakness" vulnerability in RC4 stream cipher | LOW | 3.7 | Apr 1, 2015 |
| CVE-2015-0235 | glibc: __nss_hostname_digits_dots() heap-based buffer overflow | HIGH | 10.0 | Jan 28, 2015 |
| CVE-2013-2566 | SSL/TLS: Attack against RC4 stream cipher | MEDIUM | 5.9 | Mar 14, 2013 |
Showing 1 to 20 of 20 CVEs