VendorsOraclecommunications_messaging_server8.1
Vulnerabilities

Oracle Communications Messaging Server 8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2022-23305
SQL injection in JDBC Appender in Apache Log4j V1
Published 2022-01-18 · Modified
9.8EPSS 0.665
CVE-2019-0228
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.
Published 2019-04-17 · Modified
9.8EPSS 0.095
CVE-2020-11656
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
Published 2020-04-09 · Modified
9.8EPSS 0.076
CVE-2022-23307
A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.
Published 2022-01-18 · Modified
9.0EPSS 0.544
CVE-2022-23302
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
Published 2022-01-18 · Modified
8.8EPSS 0.636
CVE-2020-24616
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Published 2020-08-25 · Modified
8.1EPSS 0.076
CVE-2020-24750
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Published 2020-09-17 · Modified
8.1EPSS 0.073
CVE-2020-28052
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Published 2020-12-18 · Modified
8.1EPSS 0.072
CVE-2020-36189
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
Published 2021-01-06 · Modified
8.1EPSS 0.039
CVE-2021-4104
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
Published 2021-12-14 · Modified
7.5EPSS 0.806
CVE-2021-33813
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Published 2021-06-16 · Modified
7.5EPSS 0.194
CVE-2020-25649
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Published 2020-12-03 · Modified
7.5EPSS 0.173
CVE-2021-36090
Apache Commons Compress 1.0 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.129
CVE-2021-35516
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.124
CVE-2021-35515
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.116
CVE-2021-35517
Apache Commons Compress 1.1 to 1.20 denial of service vulnerability
Published 2021-07-13 · Modified
7.5EPSS 0.106
CVE-2020-11612
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
Published 2020-04-07 · Modified
7.5EPSS 0.094
CVE-2021-40690
Bypass of the secureValidation property
Published 2021-09-19 · Modified
7.5EPSS 0.074
CVE-2021-30468
Apache CXF Denial of service vulnerability in parsing JSON via JsonMapObjectReaderWriter
Published 2021-06-16 · Modified
7.5EPSS 0.070
CVE-2021-37714
Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions
Published 2021-08-18 · Modified
7.5EPSS 0.069
CVE-2020-13871
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
Published 2020-06-06 · Modified
7.5EPSS 0.044
CVE-2020-11655
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
Published 2020-04-09 · Modified
7.5EPSS 0.043
CVE-2020-9327
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.
Published 2020-02-21 · Modified
7.5EPSS 0.037
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Published 2019-11-08 · Modified
6.5EPSS 0.022
CVE-2021-21290
Local Information Disclosure Vulnerability in Netty on Unix-Like systems due temporary files
Published 2021-02-08 · Modified
6.2EPSS 0.018
CVE-2020-13954
Apache CXF Reflected XSS in the services listing page via the styleSheetPath
Published 2020-11-12 · Modified
6.1EPSS 0.409
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2021-21409
Possible request smuggling in HTTP/2 due missing validation of content-length
Published 2021-03-30 · Modified
5.9EPSS 0.049
CVE-2021-31811
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny file
Published 2021-06-12 · Modified
5.5EPSS 0.034
CVE-2021-27906
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file
Published 2021-03-19 · Modified
5.5EPSS 0.033
CVE-2021-31812
A carefully crafted PDF file can trigger an infinite loop while loading the file
Published 2021-06-12 · Modified
5.5EPSS 0.031
CVE-2020-1950
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
Published 2020-03-23 · Modified
5.5EPSS 0.030
CVE-2021-27807
A carefully crafted PDF file can trigger an infinite loop while loading the file
Published 2021-03-19 · Modified
5.5EPSS 0.030
CVE-2020-1951
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
Published 2020-03-23 · Modified
5.5EPSS 0.029
CVE-2021-28657
Infinite loop in Apache Tika's MP3 parser
Published 2021-03-31 · Modified
5.5EPSS 0.028
CVE-2020-9489
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.
Published 2020-04-27 · Modified
5.5EPSS 0.026
CVE-2020-15358
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Published 2020-06-27 · Modified
5.5EPSS 0.010