Known vulnerabilities in Oracle Communications Diameter Signaling Router - page 2

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_communications_diameter_signaling_router:*:*:*:*:*:*:*:*
Total vulnerabilities: 57
Public exploits: 14
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Communications Diameter Signaling Router Oracle Communications Diameter Signaling Router is affected by 57 known vulnerabilities: 3 critical, 9 high, 32 medium, 13 low Critical High Medium Low

Vulnerabilities (57)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83515 - Integer overflow
CVE-2023-37536
CWE-190 Medium
No
No
- 27.11.2023 SB2023112767
SB2023112803
SB2023112809
and 28 more
#VU78978 - Memory corruption
CVE-2023-3824
CWE-119 Critical
Available
Exploited
- 06.08.2023 SB2023080604
SB2023081704
SB20230821142
and 32 more
#VU78454 - Untrusted Search Path
CVE-2023-38408
CWE-426 Medium
Available
No
- 20.07.2023 SB2023072068
SB2023072073
SB2023072074
and 73 more
#VU77622 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34981
CWE-200 Medium
No
No
- 22.06.2023 SB2023062241
SB2023070714
SB2023071901
and 24 more
#VU75486 - Improper input validation
CVE-2023-29007
CWE-20 Low
Available
No
- 25.04.2023 SB2023042553
SB2023042610
SB2023042629
and 48 more
#VU74824 - Double Free
CVE-2023-1999
CWE-415 High
No
No
- 11.04.2023 SB2023041129
SB2023041192
SB2023042845
and 40 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
- 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72250 - Out-of-bounds write
CVE-2023-0767
CWE-787 Medium
No
No
- 15.02.2023 SB2023021549
SB2023021551
SB2023021552
and 84 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
- 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU71754 - Integer overflow
CVE-2022-25147
CWE-190 High
No
No
- 02.02.2023 SB2023020210
SB2023020212
SB2023020942
and 47 more
#VU71332 - Improper input validation
CVE-2023-22809
CWE-20 Low
Available
No
- 18.01.2023 SB20230118100
SB20230118104
SB20230118105
and 55 more
#VU70666 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-45143
CWE-94 Medium
No
No
- 03.01.2023 SB2023010329
SB2023012516
SB2023012606
and 34 more
#VU70444 - Server-Side Request Forgery (SSRF)
CVE-2022-46364
CWE-918 Medium
No
No
- 20.12.2022 SB2022122009
SB2023011329
SB2023011707
and 67 more
#VU69337 - Integer overflow
CVE-2022-42898
CWE-190 Medium
No
No
- 15.11.2022 SB2022111530
SB2022111610
SB2022111621
and 123 more
#VU68886 - Out-of-bounds read
CVE-2022-31630
CWE-125 Medium
No
No
- 01.11.2022 SB2022110119
SB2022110336
SB2022110814
and 21 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
- 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Available
No
- 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU61422 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-25220
CWE-350 Medium
No
No
- 17.03.2022 SB2022031701
SB2022031719
SB2022031725
and 57 more
#VU60739 - Integer overflow
CVE-2022-25315
CWE-190 High
No
No
- 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 99 more
#VU52384 - Resource exhaustion
CVE-2020-7760
CWE-400 Medium
No
No
- 21.04.2021 SB2020103047
SB2021042101
SB2021042106
and 12 more


Showing elements 21 - 40 out of 57