<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Oracle Database (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/oracle-database.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oracle-database-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Oracle Database (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:40 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46835 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46835</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46835</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46834 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46834</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46834</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46833 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46833</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46833</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerab…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42233 – n8n is an open source workflow automation platform. Prior to versions 1.123.32, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42233</guid>
    <pubDate>Mon, 04 May 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42233</strong></p>
  <p>n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the Limit field (e.g., from a web…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35229 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35229</guid>
    <pubDate>Tue, 21 Apr 2026 21:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35229</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.30 and  21.3-21.21. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Java VM accessible d…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21939 – Vulnerability in the SQLcl component of Oracle Database Server.  Supported versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21939</guid>
    <pubDate>Tue, 20 Jan 2026 22:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21939</strong></p>
  <p>Vulnerability in the SQLcl component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can resul…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10703 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10703</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10703</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.  The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver l…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10702 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10702</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10702</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.   The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50069 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50069</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50069</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27 and  21.3-21.18. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  While the vulnerability is in Java VM, attacks may significantly impact additional product…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30751 – Vulnerability in the Oracle Database component of Oracle Database Server.  Suppo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30751</guid>
    <pubDate>Tue, 15 Jul 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30751</strong></p>
  <p>Vulnerability in the Oracle Database component of Oracle Database Server.  Supported versions that are affected are 19.27  and  23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database.  Successful attacks of this vulnerability can result in takeover of Oracle Datab…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30736 – Vulnerability in the Java VM component of Oracle Database Server.  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30736</guid>
    <pubDate>Tue, 15 Apr 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30736</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26, 21.3-21.17 and  23.4-23.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to crit…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30701 – Vulnerability in the RAS Security component of Oracle Database Server.  Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30701</guid>
    <pubDate>Tue, 15 Apr 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30701</strong></p>
  <p>Vulnerability in the RAS Security component of Oracle Database Server.  Supported versions that are affected are 19.3-19.26, 21.3-21.17 and  23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via Oracle Net to compromise RAS Security.  Successful attacks require human interaction from a person other than the attacker. Succe…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-53908 – An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53908</guid>
    <pubDate>Fri, 06 Dec 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-53908</strong></p>
  <p>An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21184 – Vulnerability in the Oracle Database RDBMS Security component of Oracle Database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21184</guid>
    <pubDate>Tue, 16 Jul 2024 23:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21184</strong></p>
  <p>Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server.  Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security.  Successful attacks of this vulnerability can result in takeover of Or…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-21893 – Vulnerability in the Oracle Data Provider for .NET component of Oracle Database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-21893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-21893</guid>
    <pubDate>Wed, 18 Jan 2023 00:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-21893</strong></p>
  <p>Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-21893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21603 – Vulnerability in the Oracle Database - Sharding component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21603</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21603</strong></p>
  <p>Vulnerability in the Oracle Database - Sharding component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Local Logon to compromise Oracle Database - Sharding. Successful attacks of this vulnerability can result in takeover of Oracle Database - Sha…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21596 – Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21596</guid>
    <pubDate>Tue, 18 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21596</strong></p>
  <p>Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having DBA user privilege with network access via Oracle Net to compromise Oracle Database - Advanced Queuing. Successful attacks of this vulnerability can result in takeover of Oracle Database…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21511 – Vulnerability in the Oracle Database - Enterprise Edition Recovery component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21511</guid>
    <pubDate>Tue, 19 Jul 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21511</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Recovery component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows high privileged attacker having EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Recovery. Successful attacks of this vul…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21510 – Vulnerability in the Oracle Database - Enterprise Edition Sharding component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21510</guid>
    <pubDate>Tue, 19 Jul 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21510</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Oracle Database - Enterprise Edition Sharding executes to compromise Oracle Database - Enterprise Edition Shardi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21410 – Vulnerability in the Oracle Database - Enterprise Edition Sharding component of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21410</guid>
    <pubDate>Tue, 19 Apr 2022 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21410</strong></p>
  <p>Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Sharding. Successful attacks of this vulnerability can resu…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-42064 – If configured to use an Oracle database and if a query is created using the flex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42064</guid>
    <pubDate>Tue, 14 Dec 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-42064</strong></p>
  <p>If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35619 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35619</guid>
    <pubDate>Wed, 20 Oct 2021 11:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35619</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other than the attacker. Successful attack…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35599 – Vulnerability in the Zero Downtime DB Migration to Cloud component of Oracle Dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35599</guid>
    <pubDate>Wed, 20 Oct 2021 11:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35599</strong></p>
  <p>Vulnerability in the Zero Downtime DB Migration to Cloud component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Zero Downtime DB Migration to Cloud executes to compromise Zero Downtime DB Migration to Cloud. While the vulnerability is in…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2351 – Vulnerability in the Advanced Networking Option component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2351</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2351</strong></p>
  <p>Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vuln…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2337 – Vulnerability in the Oracle XML DB component of Oracle Database Server. Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2337</guid>
    <pubDate>Wed, 21 Jul 2021 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2337</strong></p>
  <p>Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulnerability can result in takeover of O…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2329 – Vulnerability in the Oracle XML DB component of Oracle Database Server. Supporte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2329</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2329</strong></p>
  <p>Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulnerability can result in takeover of O…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2328 – Vulnerability in the Oracle Text component of Oracle Database Server. Supported ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2328</guid>
    <pubDate>Wed, 21 Jul 2021 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2328</strong></p>
  <p>Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2054 – Vulnerability in the RDBMS Sharding component of Oracle Database Server. Support...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2054</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2054</strong></p>
  <p>Vulnerability in the RDBMS Sharding component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Any View, Create Any Trigger privilege with network access via Oracle Net to compromise RDBMS Sharding. Successful attacks of this vulnerability can result in ta…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2035 – Vulnerability in the RDBMS Scheduler component of Oracle Database Server. Suppor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2035</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2035</strong></p>
  <p>Vulnerability in the RDBMS Scheduler component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Export Full Database privilege with network access via Oracle Net to compromise RDBMS Scheduler. Successful attacks of this vulnerability can result in takeover of RDBMS Scheduler.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-2018 – Vulnerability in the Advanced Networking Option component of Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-2018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-2018</guid>
    <pubDate>Wed, 20 Jan 2021 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-2018</strong></p>
  <p>Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-2018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14735 – Vulnerability in the Scheduler component of Oracle Database Server. Supported ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14735</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14735</strong></p>
  <p>Vulnerability in the Scheduler component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Scheduler executes to compromise Scheduler. While the vulnerability is in Scheduler, attacks may significantly impa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14734 – Vulnerability in the Oracle Text component of Oracle Database Server. Supported ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14734</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14734</strong></p>
  <p>Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentia…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2968 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2968</guid>
    <pubDate>Wed, 15 Jul 2020 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2968</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks require human interaction from a person other th…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2735 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2735</guid>
    <pubDate>Wed, 15 Apr 2020 14:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2735</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other than the attacker and while…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2518 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2518</guid>
    <pubDate>Wed, 15 Jan 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2518</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2511 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2511</guid>
    <pubDate>Wed, 15 Jan 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2511</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. Succ…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2510 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2510</guid>
    <pubDate>Wed, 15 Jan 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2510</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via OracleNet to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerab…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2799 – Vulnerability in the Oracle ODBC Driver component of Oracle Database Server&lt;span...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2799</guid>
    <pubDate>Tue, 23 Jul 2019 23:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2799</strong></p>
  <p>Vulnerability in the Oracle ODBC Driver component of Oracle Database Server<span class=font-red><b> ***PRIVILEGE CANNOT BE NONE FOR AUTHENTICATED ATTACKS***</b></span>. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Oracle…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2776 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2776</guid>
    <pubDate>Tue, 23 Jul 2019 23:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2776</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Index privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. S…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2619 – Vulnerability in the Portable Clusterware component of Oracle Database Server. S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2619</guid>
    <pubDate>Tue, 23 Apr 2019 19:32:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2619</strong></p>
  <p>Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2518 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2518</guid>
    <pubDate>Tue, 23 Apr 2019 19:32:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2518</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-2517 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2517</guid>
    <pubDate>Tue, 23 Apr 2019 19:32:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-2517</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having DBFS_ROLE privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. Successful attacks of…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2516 – Vulnerability in the Portable Clusterware component of Oracle Database Server. S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2516</guid>
    <pubDate>Tue, 23 Apr 2019 19:32:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2516</strong></p>
  <p>Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2444 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2444</guid>
    <pubDate>Wed, 16 Jan 2019 19:30:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2444</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker and while…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2406 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2406</guid>
    <pubDate>Wed, 16 Jan 2019 19:30:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2406</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in takeover of Core RDBMS. CV…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-3299 – Vulnerability in the Oracle Text component of Oracle Database Server. Supported ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3299</guid>
    <pubDate>Wed, 17 Oct 2018 01:31:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-3299</strong></p>
  <p>Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Text. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Ora…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-3259 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3259</guid>
    <pubDate>Wed, 17 Oct 2018 01:31:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-3259</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.8 (Confidentiality, Integ…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-3110 – A vulnerability was discovered in the Java VM component of Oracle Database Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3110</guid>
    <pubDate>Fri, 10 Aug 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-3110</strong></p>
  <p>A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional p…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-2939 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-2939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-2939</guid>
    <pubDate>Wed, 18 Jul 2018 13:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-2939</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantl…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-2939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-2841 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-2841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-2841</guid>
    <pubDate>Thu, 19 Apr 2018 02:29:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-2841</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact addit…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-2841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-2680 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-2680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-2680</guid>
    <pubDate>Thu, 18 Jan 2018 02:29:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-2680</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java VM,…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-2680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-10282 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10282</guid>
    <pubDate>Thu, 18 Jan 2018 02:29:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-10282</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-10321 – Vulnerability in the Core RDBMS component of Oracle Database Server. Supported v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10321</guid>
    <pubDate>Thu, 19 Oct 2017 17:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-10321</strong></p>
  <p>Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-10190 – Vulnerability in the Java VM component of Oracle Database Server. Supported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10190</guid>
    <pubDate>Thu, 19 Oct 2017 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-10190</strong></p>
  <p>Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Java VM executes to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-10202 – Vulnerability in the OJVM component of Oracle Database Server. Supported version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-10202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-10202</guid>
    <pubDate>Tue, 08 Aug 2017 15:29:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-10202</strong></p>
  <p>Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks may significantly impact additional produ…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-10202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-3486 – Vulnerability in the SQL*Plus component of Oracle Database Server. Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3486</guid>
    <pubDate>Mon, 24 Apr 2017 19:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-3486</strong></p>
  <p>Vulnerability in the SQL*Plus component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where SQL*Plus executes to compromise SQL*Plus. Successful attacks require human interaction from a person other than the attacker and whil…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-3310 – Vulnerability in the OJVM component of Oracle Database Server. Supported version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3310</guid>
    <pubDate>Fri, 27 Jan 2017 22:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-3310</strong></p>
  <p>Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. Successful attacks require human interaction from a person other than the attacker and while th…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9013 – Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9013</guid>
    <pubDate>Fri, 09 Dec 2016 20:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9013</strong></p>
  <p>Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5555 – Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5555</guid>
    <pubDate>Tue, 25 Oct 2016 14:30:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5555</strong></p>
  <p>Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3609 – Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3609</guid>
    <pubDate>Thu, 21 Jul 2016 10:14:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3609</strong></p>
  <p>Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3506 – Unspecified vulnerability in the JDBC component in Oracle Database Server 11.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3506</guid>
    <pubDate>Thu, 21 Jul 2016 10:12:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3506</strong></p>
  <p>Unspecified vulnerability in the JDBC component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2; the Oracle Retail Xstore Point of Service 5.5, 6.0, 6.5, 7.0, 7.1, 15.0, and 16.0; the Oracle Retail Warehouse Management System 14.04, 14.1.3, and 15.0.1; the Oracle Retail Workforce Management 1.60.7, and 1.64.0; the Oracle Retail Clearance Optimization Engine 13.4; the Oracle Retail Mark…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3479 – Unspecified vulnerability in the Portable Clusterware component in Oracle Databa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3479</guid>
    <pubDate>Thu, 21 Jul 2016 10:12:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3479</strong></p>
  <p>Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-3454 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3454</guid>
    <pubDate>Thu, 21 Apr 2016 11:00:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-3454</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0681 – Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0681</guid>
    <pubDate>Thu, 21 Apr 2016 10:59:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0681</strong></p>
  <p>Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-0499 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0499</guid>
    <pubDate>Thu, 21 Jan 2016 03:00:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-0499</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4794.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4873 – Unspecified vulnerability in the Database Scheduler component in Oracle Database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4873</guid>
    <pubDate>Wed, 21 Oct 2015 23:59:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4873</strong></p>
  <p>Unspecified vulnerability in the Database Scheduler component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-4863 – Unspecified vulnerability in the Portable Clusterware component in Oracle Databa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4863</guid>
    <pubDate>Wed, 21 Oct 2015 23:59:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-4863</strong></p>
  <p>Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-4796 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4796</guid>
    <pubDate>Wed, 21 Oct 2015 21:59:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-4796</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4888.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-4794 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4794</guid>
    <pubDate>Wed, 21 Oct 2015 21:59:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-4794</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-2629 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2629</guid>
    <pubDate>Thu, 16 Jul 2015 10:59:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-2629</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-0457.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-0457 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0457</guid>
    <pubDate>Thu, 16 Apr 2015 16:59:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-0457</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-2629.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6567 – Unspecified vulnerability in the Core RDBMS component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6567</guid>
    <pubDate>Wed, 21 Jan 2015 15:28:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6567</strong></p>
  <p>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that this is a stack-based buffer overflow…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6560 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6560</guid>
    <pubDate>Wed, 15 Oct 2014 22:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6560</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6467, and CVE-2014-6545.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6546 – Unspecified vulnerability in the JPublisher component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6546</guid>
    <pubDate>Wed, 15 Oct 2014 22:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6546</strong></p>
  <p>Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6545 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6545</guid>
    <pubDate>Wed, 15 Oct 2014 22:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6545</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6467, and CVE-2014-6560.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6467 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6467</guid>
    <pubDate>Wed, 15 Oct 2014 15:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6467</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6545, and CVE-2014-6560.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6455 – Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6455</guid>
    <pubDate>Wed, 15 Oct 2014 15:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6455</strong></p>
  <p>Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-6453 – Unspecified vulnerability in the Java VM component in Oracle Database Server 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6453</guid>
    <pubDate>Wed, 15 Oct 2014 15:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-6453</strong></p>
  <p>Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6467, CVE-2014-6545, and CVE-2014-6560.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-2406 – Unspecified vulnerability in the Core RDBMS component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2406</guid>
    <pubDate>Wed, 16 Apr 2014 01:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-2406</strong></p>
  <p>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to "Advisor" and "Select Any Dictionary" privileges.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3774 – Unspecified vulnerability in the Network Layer component in Oracle Database Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3774</guid>
    <pubDate>Wed, 17 Jul 2013 13:41:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3774</strong></p>
  <p>Unspecified vulnerability in the Network Layer component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3771 – Unspecified vulnerability in the Oracle executable component in Oracle Database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3771</guid>
    <pubDate>Wed, 17 Jul 2013 13:41:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3771</strong></p>
  <p>Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-3760.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-3760 – Unspecified vulnerability in the Oracle executable component in Oracle Database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3760</guid>
    <pubDate>Wed, 17 Jul 2013 13:41:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-3760</strong></p>
  <p>Unspecified vulnerability in the Oracle executable component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-3771.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-3751 – Unspecified vulnerability in the XML Parser component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3751</guid>
    <pubDate>Wed, 17 Jul 2013 13:41:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-3751</strong></p>
  <p>Unspecified vulnerability in the XML Parser component in Oracle Database Server 11.2.0.2, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-1534 – Unspecified vulnerability in the Workload Manager component in Oracle Database S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1534</guid>
    <pubDate>Wed, 17 Apr 2013 12:19:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-1534</strong></p>
  <p>Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0366 – Unspecified vulnerability in the Mobile Server component in Oracle Database Mobi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0366</guid>
    <pubDate>Thu, 17 Jan 2013 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0366</strong></p>
  <p>Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0361.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0364 – Unspecified vulnerability in the Mobile Server component in Oracle Database Mobi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0364</guid>
    <pubDate>Thu, 17 Jan 2013 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0364</strong></p>
  <p>Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0363.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0363 – Unspecified vulnerability in the Mobile Server component in Oracle Database Mobi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0363</guid>
    <pubDate>Thu, 17 Jan 2013 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0363</strong></p>
  <p>Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0362 and CVE-2013-0364.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0362 – Unspecified vulnerability in the Mobile Server component in Oracle Database Mobi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0362</guid>
    <pubDate>Thu, 17 Jan 2013 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0362</strong></p>
  <p>Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-0361 – Unspecified vulnerability in the Mobile Server component in Oracle Database Mobi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0361</guid>
    <pubDate>Thu, 17 Jan 2013 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-0361</strong></p>
  <p>Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0366.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-3220 – Unspecified vulnerability in the Spatial component in Oracle Database Server 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3220</guid>
    <pubDate>Thu, 17 Jan 2013 01:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-3220</strong></p>
  <p>Unspecified vulnerability in the Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users with Create Session privileges to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-1675 – The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1675</guid>
    <pubDate>Tue, 08 May 2012 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-1675</strong></p>
  <p>The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.0.5, as used in Oracle Fusion Middleware, Enterprise Manager, E-Business Suite, and possibly other products, allows remote attackers to execute arbitrary database commands by performing a remote registration of a database (1) instance or (2) service name that already exists, the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-0552 – Unspecified vulnerability in the Oracle Spatial component in Oracle Database Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0552</guid>
    <pubDate>Thu, 03 May 2012 18:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-0552</strong></p>
  <p>Unspecified vulnerability in the Oracle Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0519 – Unspecified vulnerability in the Core RDBMS component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0519</guid>
    <pubDate>Thu, 03 May 2012 17:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0519</strong></p>
  <p>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2301 – Unspecified vulnerability in the Oracle Text component in Oracle Database Server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2301</guid>
    <pubDate>Tue, 18 Oct 2011 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2301</strong></p>
  <p>Unspecified vulnerability in the Oracle Text component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to CTXSYS.DRVDISP.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-3290 – Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle databas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-3290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-3290</guid>
    <pubDate>Wed, 21 Sep 2011 16:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-3290</strong></p>
  <p>Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-3290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2253 – Unspecified vulnerability in the Core RDBMS component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2253</guid>
    <pubDate>Wed, 20 Jul 2011 23:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2253</strong></p>
  <p>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYSDBA.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2239 – Unspecified vulnerability in the Core RDBMS component in Oracle Database Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2239</guid>
    <pubDate>Wed, 20 Jul 2011 23:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2239</strong></p>
  <p>Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability, related to XMLSEQ_IMP_T.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-3600 – Unspecified vulnerability in the Client System Analyzer component in Oracle Data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3600</guid>
    <pubDate>Wed, 19 Jan 2011 16:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-3600</strong></p>
  <p>Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU.  Oracle has not commented on claims from a reliable third party coord…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-2390 – Unspecified vulnerability in the Database Control component in EM Console in Ora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2390</guid>
    <pubDate>Thu, 14 Oct 2010 00:00:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-2390</strong></p>
  <p>Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-0911 – Unspecified vulnerability in the Listener component in Oracle Database Server 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0911</guid>
    <pubDate>Tue, 13 Jul 2010 22:30:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-0911</strong></p>
  <p>Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0911">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
