VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 16 hours ago
Reset
More filters (1)
Columns
Advisory: Oracle Critical Patch Update April 2010
Overview 47 matches · 22 in RASP scope · 0 protected · 0 KEV · 1 public PoC · 0 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
47matches 22in RASP scope46.8% 0protected0.0% 0KEV0.0% 1public PoC2.1% 0CISA SSVC0.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 8 17.0% Medium 31 66.0% Low 8 17.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 22 46.8% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 17 36.2% Out of RASP scope 8 17.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 47 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 1 2.1% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 46 97.9%
split by peak 44 / month
Unknown: 0None: 0Low: 8Medium: 31High: 8Critical: 0 Rejected: 0Out of RASP scope: 8Not applicable: 17Queued for review: 0Mitigated by environment configuration: 0No fix identified: 22No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 47blocked by ARMR today: 0 No public exploit: 46Forecast only: 0Proof of concept only: 0Working exploit published: 1Exploited in the wild: 0 May 2009: 1 CVE June 2009: 0 CVEs July 2009: 0 CVEs August 2009: 1 CVE September 2009: 0 CVEs October 2009: 0 CVEs November 2009: 0 CVEs December 2009: 0 CVEs January 2010: 0 CVEs February 2010: 1 CVE March 2010: 0 CVEs April 2010: 44 CVEs
May 09Jun 09Jul 09Aug 09Sep 09Oct 09Nov 09Dec 09Jan 10Feb 10Mar 10Apr 10
47 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2010-0881 Medium 2010-04-14 Not applicable No public exploit Unspecified vulnerability in the User Interface Components in Oracle Collaboration Suite 10.1.2.4 allows remote attackers to affect integrity via unknown vectors.
CVE-2010-0897 High 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Java System Directory Server component in Oracle Sun Product Suite 5.2, 6.0, 6.1, 6.2, 6.3, and 6.3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Directory Service Markup Language.
CVE-2010-0896 High 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Convergence component in Oracle Sun Product Suite 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Address Book and Mail Filter.
CVE-2010-0895 Low 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite OpenSolaris snv_119 allows local users to affect integrity and availability via unknown vectors related to IP Filter.
CVE-2010-0894 Medium 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Java System Access Manager component in Oracle Sun Product Suite 7.1, 7 2005Q4, and OpenSSO Enterprise 8.0 allows remote attackers to affect confidentiality and integrity via unknown vectors.
CVE-2010-0893 Medium 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Convergence component in Oracle Sun Product Suite 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail.
CVE-2010-0891 Medium 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Management Center component in Oracle Sun Product Suite 3.6.1 and 4.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Solaris Container Manager.
CVE-2010-0890 Low 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_01 through snv_98 allows local users to affect availability via unknown vectors related to the Kernel.
CVE-2010-0889 Medium 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite OpenSolaris snv_68 through snv_128 allows local users to affect confidentiality via unknown vectors related to the Kernel.
CVE-2010-0888 High 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Ray Server Software component in Oracle Sun Product Suite 4.0, 4.1, and 4.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Device Services.
CVE-2010-0885 Medium 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Java System Communications Express component in Oracle Sun Product Suite 6 2005Q4 (6.2) and and 6.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Address Book.
CVE-2010-0884 Low 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Cluster component in Oracle Sun Product Suite 3.1 and 3.2 allows local users to affect confidentiality via unknown vectors related to Data Service for Oracle E-Business Suite, a different vulnerability than CVE-2010-0883.
CVE-2010-0883 Low 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Sun Cluster component in Oracle Sun Product Suite 3.1 and 3.2 allows local users to affect confidentiality via unknown vectors related to Data Service for Oracle E-Business Suite, a different vulnerability than CVE-2010-0884.
CVE-2010-0882 High 2010-04-13 Not applicable No public exploit Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_134 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Trusted Extensions.
CVE-2010-0880 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote attackers to affect confidentiality and integrity via unknown vectors.
CVE-2010-0879 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote authenticated users to affect confidentiality via unknown vectors.
CVE-2010-0878 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote authenticated users to affect integrity via unknown vectors.
CVE-2010-0877 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote attackers to affect integrity via unknown vectors.
CVE-2010-0876 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Life Sciences - Oracle Clinical Remote Data Capture Option component in Oracle Industry Product Suite 4.5.3 and 4.6 allows remote attackers to affect integrity, related to RDC Onsite.
CVE-2010-0875 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Life Sciences - Oracle Thesaurus Management System component in Oracle Industry Product Suite 4.5.2, 4.6, and 4.6.1 allows remote attackers to affect integrity, related to TMS Browser.
CVE-2010-0874 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Communications - Oracle Communications Unified Inventory Management component in Oracle Industry Product Suite 7.1 allows remote attackers to affect integrity via unknown vectors.
CVE-2010-0872 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle Internet Directory component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3 allows remote attackers to affect availability via unknown vectors.
CVE-2010-0871 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.
CVE-2010-0870 Low 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.
CVE-2010-0869 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle Transportation Management component in Oracle E-Business Suite 5.5.05.07, 5.5.06.00, and 6.0.03 allows remote attackers to affect confidentiality via unknown vectors.
CVE-2010-0868 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
CVE-2010-0867 Medium 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.1.0 allows remote authenticated users to affect integrity via unknown vectors.
CVE-2010-0866 Medium 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2010-0865 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Business Suite 6.1.1.0 allows remote attackers to affect confidentiality via unknown vectors.
CVE-2010-0864 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Retail - Oracle Retail Place In-Season component in Oracle Industry Product Suite 12.2 allows remote attackers to affect integrity via unknown vectors related to Online Help.
CVE-2010-0863 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Retail - Oracle Retail Plan In-Season component in Oracle Industry Product Suite 12.2 allows remote attackers to affect integrity via unknown vectors related to Online Help.
CVE-2010-0862 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Retail - Oracle Retail Markdown Optimization component in Oracle Industry Product Suite 13.1 allows remote attackers to affect integrity via unknown vectors related to Online Help.
CVE-2010-0861 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle HRMS (Self Service) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality via unknown vectors.
CVE-2010-0860 High 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to the Create User privilege.
CVE-2010-0859 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 ATG RUP6 allows remote attackers to affect confidentiality and integrity via unknown vectors.
CVE-2010-0858 Low 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors.
CVE-2010-0857 Low 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Oracle Workflow Cartridge component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors.
CVE-2010-0856 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.2 allows remote attackers to affect availability via unknown vectors.
CVE-2010-0855 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-0086.
CVE-2010-0854 Low 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."
CVE-2010-0853 High 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2.0.8, and DV; and Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2010-0852 Medium 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
CVE-2010-0851 Medium 2010-04-13 Out of RASP scope No public exploit Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality via unknown vectors.
CVE-2010-0086 Medium 2010-04-13 No fix identified No public exploit Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-0855.
CVE-2010-0453 Medium 2010-02-03 Not applicable Working exploit published The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.
CVE-2009-2404 High 2009-08-03 Not applicable No public exploit Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.
CVE-2009-0688 High 2009-05-15 Not applicable No public exploit Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.