Oracle / Utilities Framework
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-21924 | Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General). Supported versions that are affected… | MEDIUM | 5.4 | Jan 20, 2026 |
| CVE-2020-36518 | jackson-databind: denial of service via a large depth of nested objects | HIGH | 7.5 | Mar 11, 2022 |
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-39150 | A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39152 | A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39140 | XStream can cause a Denial of Service | MEDIUM | 6.5 | Aug 23, 2021 |
| CVE-2021-39149 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39148 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39147 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39146 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39145 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39141 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39153 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39151 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39139 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.8 | Aug 23, 2021 |
| CVE-2021-39154 | XStream is vulnerable to an Arbitrary Code Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-39144 KEV | XStream is vulnerable to a Remote Command Execution attack | HIGH | 8.5 | Aug 23, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2021-36374 | Apache Ant ZIP, and ZIP based, archive denial of service vulerability | MEDIUM | 5.5 | Jul 14, 2021 |
| CVE-2021-36373 | Apache Ant TAR archive denial of service vulnerability | MEDIUM | 5.5 | Jul 14, 2021 |
| CVE-2021-31684 | json-smart: Denial of Service in JSONParserByteArray function | HIGH | 7.5 | Jun 1, 2021 |
| CVE-2021-27568 | json-smart: uncaught exception may lead to crash or information disclosure | MEDIUM | 5.9 | Feb 23, 2021 |
| CVE-2020-14756 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.… | CRITICAL | 9.8 | Jan 20, 2021 |
| CVE-2020-28052 | bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible | HIGH | 8.1 | Dec 18, 2020 |
| CVE-2020-25649 | jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) | HIGH | 7.5 | Dec 3, 2020 |
Showing 1 to 25 of 38 CVEs