CVE detail
CVE-2016-3613
Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to OpenSSL.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
Normal 0 false false false EN-US X-NONE X-NONE Oracle Addresses 276 Security Flaws, 19 Critical in Critical Patch Update (CPU) For July 2016 Oracle on Tuesday released its Critical Patch Update (CPU) for July 2016 to address a total of 276 vulnerabilities across multiple products, including 19 critical security flaws that have a CVSS score of 9.8. This month’s Oracle CPU contains a record number of fixes, after the January 2016 set of patches established another one, at 248 security fixes. More worrying than the sheer number of addressed vulnerabilities is that 159 can be exploited remotely without authentication. Overall, the July CPU addresses 36 security issues in applications designed specifically for the Retail, Insurance, Health, Financial, and Utility industries. However, with 4 remotely exploitable vulnerabilities without authentication in sector-specific products, the Retail industry appears to have been affected the most. A total of 121 vulnerabilities were addressed in cruc…
newswww.securityweek.comJul 20, 2016, 11:42 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-35650CVSS 4.6 · Medium
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerabi…
- CVE-2021-35649CVSS 5.4 · Medium
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerabi…
- CVE-2021-2447CVSS 9.9 · Critical
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerabi…
- CVE-2021-2446CVSS 9.6 · Critical
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerabi…
- CVE-2021-33037CVSS 5.3 · Medium
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the po…
- CVE-2021-2248CVSS 10.0 · Critical
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerabi…
1 mention