VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago
Reset
More filters (1)
Columns
Advisory: Oracle Critical Patch Update October 2015
Overview 26 matches · 14 in RASP scope · 8 protected · 0 KEV · 2 public PoC · 0 CISA SSVC · 2 EPSS ≥ 0.5 · 0 disputed
26matches 14in RASP scope53.8% 8protected30.8% 0KEV0.0% 2public PoC7.7% 0CISA SSVC0.0% 2EPSS ≥ 0.57.7% 0disputed0.0%
Critical 0 0.0% High 26 100.0% Medium 0 0.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
blocked by ARMR today 8 30.8% not blocked 18 69.2% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 2 7.7% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 24 92.3%
split by peak 20 / quarter
Unknown: 0None: 0Low: 0Medium: 0High: 26Critical: 0 Rejected: 0Out of RASP scope: 7Not applicable: 5Queued for review: 0Mitigated by environment configuration: 7No fix identified: 4No exploit published: 0Mitigation candidate: 2Rule in development: 0Protected by RASP: 1 unrecorded: 0not established: 0not blocked: 18blocked by ARMR today: 8 No public exploit: 24Forecast only: 0Proof of concept only: 0Working exploit published: 2Exploited in the wild: 0 Q2 2014: 1 CVE Q3 2014: 0 CVEs Q4 2014: 1 CVE Q1 2015: 2 CVEs Q2 2015: 1 CVE Q3 2015: 1 CVE Q4 2015: 20 CVEs
Q2 14Q3 14Q4 14Q1 15Q2 15Q3 15Q4 15
26 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2015-4915 High 2015-10-22 Not applicable No public exploit Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to System Management.
CVE-2015-4901 High 2015-10-22 Out of RASP scope No public exploit Unspecified vulnerability in Oracle Java SE 8u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.
CVE-2015-4883 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI, a different vulnerability than CVE-2015-4860.
CVE-2015-4881 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2015-4835.
CVE-2015-4873 High 2015-10-21 Out of RASP scope No public exploit Unspecified vulnerability in the Database Scheduler component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2015-4868 High 2015-10-21 Protected by RASP No public exploit Unspecified vulnerability in Oracle Java SE 8u60 and Java SE Embedded 8u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
CVE-2015-4863 High 2015-10-21 Out of RASP scope No public exploit Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2015-4860 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI, a different vulnerability than CVE-2015-4883.
CVE-2015-4844 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
CVE-2015-4843 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
CVE-2015-4839 High 2015-10-21 No fix identified No public exploit Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to DB Listener, a different vulnerability than CVE-2015-4798.
CVE-2015-4835 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2015-4881.
CVE-2015-4821 High 2015-10-21 Not applicable No public exploit Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web.
CVE-2015-4819 High 2015-10-21 Not applicable No public exploit Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client programs.
CVE-2015-4805 High 2015-10-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.
CVE-2015-4798 High 2015-10-21 No fix identified No public exploit Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to DB Listener, a different vulnerability than CVE-2015-4839.
CVE-2015-4796 High 2015-10-21 Out of RASP scope No public exploit Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4888.
CVE-2015-4795 High 2015-10-21 No fix identified No public exploit Unspecified vulnerability in the Oracle Utilities Work and Asset Management component in Oracle Industry Applications 1.9.1.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Add-On Applications.
CVE-2015-4794 High 2015-10-21 Out of RASP scope No public exploit Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
CVE-2015-2608 High 2015-10-21 No fix identified No public exploit Unspecified vulnerability in (1) the Oracle Communications Diameter Signaling Router (DSR) component in Oracle Communications Applications 4.1.6 and earlier, 5.1.0 and earlier, 6.0.2 and earlier, and 7.1.0 and earlier; (2) the Oracle Communications Performance Intelligence Center Software component in Oracle Communications Applications 9.0.3 and earlier and 10.1.5 and earlier; (3) the Oracle Communications Policy Management component in Oracle Communications Applications 9.9.0 and earlier, 10.5.0 and earlier, 11.5.0 and earlier, and 12.1.0 and earlier; and (4) the Oracle Communications Tekelec HLR Router component in Oracle Communications Applications 4.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to PMAC.
CVE-2014-3576 High 2015-08-14 Mitigation candidate No public exploit The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
CVE-2015-3144 High 2015-04-24 Out of RASP scope No public exploit The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
CVE-2015-0235 High 2015-01-28 Out of RASP scope Working exploit published Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
CVE-2014-7940 High 2015-01-22 Not applicable No public exploit The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.
CVE-2014-1569 High 2014-12-15 Not applicable No public exploit The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function's improper handling of an arbitrary-length encoding of 0x00.
CVE-2014-0050 High 2014-04-01 Mitigation candidate Working exploit published MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.