VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 36 minutes ago
Reset
More filters (1)
Columns
Advisory: Oracle Critical Patch Update January 2015
Overview 25 matches · 11 in RASP scope · 8 protected · 0 KEV · 6 public PoC · 0 CISA SSVC · 2 EPSS ≥ 0.5 · 0 disputed
25matches 11in RASP scope44.0% 8protected32.0% 0KEV0.0% 6public PoC24.0% 0CISA SSVC0.0% 2EPSS ≥ 0.58.0% 0disputed0.0%
Critical 0 0.0% High 25 100.0% Medium 0 0.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 2 8.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 3 12.0% Mitigated by environment configuration 6 24.0% Queued for review 0 0.0% Not applicable 11 44.0% Out of RASP scope 3 12.0% Rejected 0 0.0%
blocked by ARMR today 8 32.0% not blocked 17 68.0% not established 0 0.0% unrecorded 0 0.0%
split by peak 16 / quarter
Unknown: 0None: 0Low: 0Medium: 0High: 25Critical: 0 Rejected: 0Out of RASP scope: 3Not applicable: 11Queued for review: 0Mitigated by environment configuration: 6No fix identified: 3No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 2 unrecorded: 0not established: 0not blocked: 17blocked by ARMR today: 8 No public exploit: 20Forecast only: 0Proof of concept only: 3Working exploit published: 2Exploited in the wild: 0 Q3 2011: 1 CVE Q4 2011: 0 CVEs Q1 2012: 0 CVEs Q2 2012: 0 CVEs Q3 2012: 0 CVEs Q4 2012: 0 CVEs Q1 2013: 1 CVE Q2 2013: 0 CVEs Q3 2013: 1 CVE Q4 2013: 2 CVEs Q1 2014: 0 CVEs Q2 2014: 2 CVEs Q3 2014: 1 CVE Q4 2014: 1 CVE Q1 2015: 16 CVEs
Q3 11Q1 12Q3 12Q1 13Q3 13Q1 14Q3 14Q1 15
25 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2015-0437 High 2015-01-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2015-0424 High 2015-01-21 Not applicable No public exploit Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite ILOM prior to 3.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to IPMI.
CVE-2015-0412 High 2015-01-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.
CVE-2015-0411 High 2015-01-21 Out of RASP scope No public exploit Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
CVE-2015-0408 High 2015-01-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.
CVE-2015-0396 High 2015-01-21 No fix identified No public exploit Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Admin Console.
CVE-2015-0395 High 2015-01-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2014-6601 High 2015-01-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2014-6598 High 2015-01-21 No fix identified Proof of concept only Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.
CVE-2014-6567 High 2015-01-21 Out of RASP scope No public exploit Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow in DBMS_AW.EXECUTE, which allows code execution via a long Current Directory Alias (CDA) command.
CVE-2014-6565 High 2015-01-21 No fix identified No public exploit Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Portal SEC.
CVE-2014-6549 High 2015-01-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
CVE-2014-6524 High 2015-01-21 Not applicable No public exploit Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.
CVE-2014-6521 High 2015-01-21 Not applicable No public exploit Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via vectors related to CDE - Power Management Utility.
CVE-2014-6510 High 2015-01-21 Not applicable No public exploit Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility.
CVE-2014-4259 High 2015-01-21 Not applicable No public exploit Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to System management.
CVE-2014-3567 High 2014-10-19 Not applicable No public exploit Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted session ticket that triggers an integrity-check failure.
CVE-2014-1568 High 2014-09-25 Not applicable No public exploit Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
CVE-2014-0224 High 2014-06-05 Out of RASP scope Proof of concept only OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
CVE-2014-0114 High 2014-04-30 Protected by RASP Working exploit published Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
CVE-2013-1741 High 2013-11-18 Not applicable No public exploit Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
CVE-2013-2186 High 2013-10-28 Protected by RASP Proof of concept only The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
CVE-2013-4784 High 2013-07-08 Not applicable No public exploit The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
CVE-2010-5107 High 2013-03-07 Not applicable No public exploit The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.
CVE-2011-1944 High 2011-09-02 Not applicable Working exploit published Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.