Known vulnerabilities in Communications Unified Assurance - page 4

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:communications_unified_assurance:*:*:*:*:*:*:*:*
Total vulnerabilities: 145
Public exploits: 22
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Communications Unified Assurance Communications Unified Assurance is affected by 145 known vulnerabilities: 5 critical, 27 high, 88 medium, 25 low Critical High Medium Low

Vulnerabilities (145)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113156 - Memory corruption
CVE-2025-6965
CWE-119 Medium
No
No
- 22.07.2025 SB2025072254
SB2025072807
SB2025072890
and 100 more
#VU112915 - Improper input validation
CVE-2024-34517
CWE-20 Medium
No
No
- 16.07.2025 SB2025071613
#VU112146 - Server-Side Request Forgery (SSRF)
CVE-2025-27817
CWE-918 High
Available
No
- 03.07.2025 SB2025070339
SB2025070340
SB2025070345
and 42 more
#VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4517
CWE-22 High
Available
No
- 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 77 more
#VU111165 - Improper Access Control
CVE-2025-48734
CWE-284 Medium
No
No
- 16.06.2025 SB2025061643
SB2025061644
SB2025061645
and 141 more
#VU111161 - Resource exhaustion
CVE-2025-48988
CWE-400 Medium
Available
No
- 16.06.2025 SB2025061634
SB2025061927
SB20250620145
and 40 more
#VU108769 - Resource exhaustion
CVE-2025-27533
CWE-400 Medium
Available
No
- 07.05.2025 SB2025050773
SB2025051670
SB2025062647
and 13 more
#VU107596 - Heap-based Buffer Overflow
CVE-2025-32415
CWE-122 High
No
No
- 17.04.2025 SB2025041758
SB2025041880
SB2025042531
and 56 more
#VU106926 - Resource Management Errors
CVE-2024-57699
CWE-399 Medium
No
No
- 03.04.2025 SB2025040317
SB2025040325
SB2025040326
and 63 more
#VU105987 - Improper input validation
CVE-2025-1974
CWE-20 Critical
Available
No
- 24.03.2025 SB2025032478
SB20250416107
SB2025060659
and 2 more
#VU105783 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-26791
CWE-79 Low
No
No
- 17.03.2025 SB2025031740
SB2025031741
SB2025031771
and 35 more
#VU105723 - Stack-based buffer overflow
CVE-2024-8176
CWE-121 High
No
No
- 14.03.2025 SB2025031426
SB2025031429
SB2025031430
and 105 more
#VU105715 - Out-of-bounds write
CVE-2025-27363
CWE-787 Critical
Available
Exploited
- 14.03.2025 SB2025031402
SB2025031502
SB2025031750
and 97 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
- 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU103324 - Permissions, Privileges, and Access Controls
CVE-2025-24814
CWE-264 Low
No
No
- 27.01.2025 SB2025012737
SB2025041544
SB2025071613
and 1 more
#VU101829 - Improper Authentication
CVE-2024-56128
CWE-287 Medium
No
No
- 18.12.2024 SB2024121826
SB2025041647
SB2025041651
and 12 more
#VU101654 - Exposure of sensitive information to an unauthorized actor
CVE-2024-11053
CWE-200 Low
No
No
- 11.12.2024 SB2024121137
SB2024121189
SB2024121190
and 32 more
#VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-9287
CWE-78 Low
No
No
- 28.10.2024 SB2024102836
SB2024102838
SB20241101111
and 117 more
#VU98757 - Out-of-bounds write
CVE-2024-9143
CWE-787 Low
No
No
- 16.10.2024 SB20241016108
SB2024102219
SB2024102417
and 58 more
#VU95131 - Out-of-bounds read
CVE-2024-7264
CWE-125 Medium
No
No
- 01.08.2024 SB2024080110
SB2024080117
SB20240805104
and 43 more


Showing elements 61 - 80 out of 145