A vulnerability was found in OpenSSL 3.0.0. It has been rated as problematic. Affected by this issue is the function X509_verify_cert of the component libssl. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2021-4044. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenSSL 3.0.0/3.0.1/3.0.2 and classified as problematic. Affected by this issue is the function OPENSSL_LH_flush of the component Hash Table Handler. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2022-1473. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenSSL 3.0.0/3.0.1/3.0.2. It has been classified as critical. This affects the function OCSP_basic_verify of the component OCSP Response Handler. The manipulation leads to improper certificate validation.
This vulnerability is uniquely identified as CVE-2022-1343. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenSSL 3.0.0/3.0.1/3.0.2. It has been declared as critical. This vulnerability affects unknown code of the component RC4-MD5. The manipulation leads to insufficient verification of data authenticity.
This vulnerability was named CVE-2022-1434. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle JD Edwards World Security A9.4. It has been rated as very critical. This issue affects some unknown processing of the component World Software Security. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2022-2274. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as very critical has been found in OpenSSL 3.0.4 on 64-bit. Affected is the function ossl_rsaz_mod_exp_avx512_x2 of the file rsaz_exp_x2.c of the component RSA Private Key Handler. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2022-2274. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as very critical has been found in Oracle Essbase 21.4. This affects an unknown part of the component Essbase Web Platform. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2022-2274. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Oracle HTTP Server 12.2.1.4.0. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component SSL Module. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2022-2274. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Oracle Siebel CRM up to 22.10. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Siebel Core - Server Infrastructure. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2022-2274. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Oracle JD Edwards EnterpriseOne Tools. It has been declared as very critical. This vulnerability affects unknown code of the component Enterprise Infrastructure SEC. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2022-2274. The attack can be initiated remotely. There is no exploit available.
A vulnerability has been found in OpenSSL up to 3.0.5 and classified as problematic. This vulnerability affects the function EVP_CIPHER_meth_new of the component Custom Cipher Handler. The manipulation leads to missing encryption of sensitive data.
This vulnerability was named CVE-2022-3358. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenSSL up to 3.0.7 and classified as problematic. This issue affects the function X509_VERIFY_PARAM_add0_policy of the component X.509 Certificate Handler. The manipulation leads to improper locking.
The identification of this vulnerability is CVE-2022-3996. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Combodo iTop 1.1.181/1.2.0. Affected by this issue is some unknown functionality of the file UI.php. The manipulation of the argument suggest_pwd leads to cross site scripting.
This vulnerability is handled as CVE-2011-4275. The attack may be launched remotely. Furthermore, there is an exploit available.