Page 7 of 65 results (0.007 seconds)

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

20 Apr 2011 — Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 and 11.1.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Midtier Infrastructure. Vulnerabilidad no especificada en el componente Portal de Oracle Fusion Middleware v10.1.2.3 y v11.1.1.2.0, permite a atacantes remotos afectar a la integridad a través de vectores desconocidos relacionados con Midtier Infrastructure. • http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html •

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

19 Jan 2011 — Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.0, 10.1.3.4.1, and 11.1.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Server. Vulnerabilidad no especificada en el componente Oracle BI Publisher para Oracle Fusion Middleware v10.1.3.4.0, v10.1.3.4.1 y v11.1.1.3 permite a usuarios autenticados remotamente afectar a la integridad a través de vectores desconocidos relacionados con Web Server. • http://osvdb.org/70561 •

CVSS: 8.1EPSS: 0%CPEs: 3EXPL: 0

19 Jan 2011 — Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 10.1.2.3, 11.1.1.2.0, and 11.1.1.3.0 allows remote authenticated users to affect confidentiality and integrity, related to EUL Code & Schema. Vulnerabilidad no especificada en el componente Oracle Discoverer para Oracle Fusion Middleware v10.1.2.3, v11.1.1.2.0, v11.1.1.3.0 y permite a usuarios autenticados remotamente afectar a la confidencialidad y la integridad, relacionado con EUL Code & Schema. • http://secunia.com/advisories/42994 •

CVSS: 7.5EPSS: 1%CPEs: 3EXPL: 0

13 Oct 2010 — Unspecified vulnerability in the OID component in Oracle Fusion Middleware 10.1.2.3, 10.1.4.3, and 11.1.1.2.0 allows remote attackers to affect availability via unknown vectors. Vulnerabilidad no especificada en el componente OID en Oracle Fusion Middleware v10.1.2.3, vv10.1.4.3 y v11.1.1.2.0 y permite a atacantes remotos afectar a la disponibilidad a través de vectores desconocidos. • http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html •

CVSS: 7.5EPSS: 3%CPEs: 14EXPL: 8

21 Jun 2010 — SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file. SpringSource Spring Framework v2.5.x anteriores a v2.5.6.SEC02, v2.5.7 anteriores a v2.5.7.SR01, y v3.0.x anteriores a v3.0.3 permite a atacantes remotos ejecutar código arbitrario a través de una petición HTTP que contenga class.classLoader.URLs[0]=jar:... • https://www.exploit-db.com/exploits/13918 • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE-96: Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') •