Skip to main content

Vendor/product archive

oracle / secure_global_desktop CVEs

Beta · best-effort

27 CVEs tagged to oracle / secure_global_desktop10 Critical, 2 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2021-35650

Published Oct 20, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerabi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35649

Published Oct 20, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerabi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-2447

Published Jul 21, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerabi…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-2446

Published Jul 21, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerabi…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-2248

Published Apr 22, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerabi…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-2221

Published Apr 22, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerabi…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-2177

Published Apr 22, 2021

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Gateway). The supported version that is affected is 5.6. Easily exploitable vulnerab…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10092

Published Sep 26, 2019

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be…

CVSS 6.1 · Medium

CVE-2018-16890

Published Feb 6, 2019

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode…

CVSS 7.5 · High

CVE-2018-19439

Published Dec 13, 2018

XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later versions including 5.4). helpwindow.jsp has reflected XSS via a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11763

Published Sep 25, 2018

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout co…

CVSS 5.9 · Medium

CVE-2018-1304

Published Feb 28, 2018

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49…

CVSS 5.9 · Medium

CVE-2017-7668

Published Jun 20, 2017

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input st…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-5580

Published Oct 25, 2016

Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3613

Published Jul 21, 2016

Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect confidentiality, integrity,…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-0501

Published Jan 21, 2016

Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.2 allows remote attackers to affect availability via vectors related to SGD Core.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2