Skip to main content

Vendor/product archive

oracle / graalvm CVEs

Beta · best-effort

186 CVEs tagged to oracle / graalvm5 Critical, 56 High, 79 Medium, 46 Low, 0 Unrated.

CVE-2020-14718

Published Jul 15, 2020

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: JVMCI). Supported versions that are affected are 19.3.2 and 20.1.0. Easily exploitable…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11080

Published Jun 3, 2020

In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a S…

CVSS 3.7 · Low

CVE-2020-2900

Published Apr 15, 2020

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Tools). Supported versions that are affected are 19.3.1 and 20.0.0. Difficult to explo…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-2802

Published Apr 15, 2020

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Easily…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2799

Published Apr 15, 2020

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). Supported versions that are affected are 19.3.1 and 20.0.0. Difficu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17561

Published Mar 30, 2020

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" version…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17560

Published Mar 30, 2020

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-2595

Published Jan 15, 2020

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: GraalVM Compiler). The supported version that is affected is 19.3.0.2. Easily exploita…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2581

Published Jan 15, 2020

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: LLVM Interpreter). The supported version that is affected is 19.3.0.2. Easily exploita…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 186 CVEsPage 7 of 8