Total vulnerabilities in the database
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
Software | From | Fixed in |
---|---|---|
vt / cryptacular | 1.2.0 | 1.2.4 |
vt / cryptacular | - | 1.1.4 |
oracle / webcenter_sites | 12.2.1.3.0 | 12.2.1.3.0.x |
oracle / weblogic_server | 12.2.1.4.0 | 12.2.1.4.0.x |
oracle / webcenter_sites | 12.2.1.4.0 | 12.2.1.4.0.x |
oracle / weblogic_server | 14.1.1.0.0 | 14.1.1.0.0.x |
oracle / communications_services_gatekeeper | 7.0 | 7.0.x |
![]() |
- | 1.1.4 |
![]() |
1.2.0 | 1.2.4 |