296,746
Total vulnerabilities in the database
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
| Software | From | Fixed in |
|---|---|---|
| vt / cryptacular | 1.2.0 | 1.2.4 |
| vt / cryptacular | - | 1.1.4 |
| oracle / webcenter_sites | 12.2.1.3.0 | 12.2.1.3.0.x |
| oracle / weblogic_server | 12.2.1.4.0 | 12.2.1.4.0.x |
| oracle / webcenter_sites | 12.2.1.4.0 | 12.2.1.4.0.x |
| oracle / weblogic_server | 14.1.1.0.0 | 14.1.1.0.0.x |
| oracle / communications_services_gatekeeper | 7.0 | 7.0.x |
org.cryptacular / cryptacular
|
- | 1.1.4 |
org.cryptacular / cryptacular
|
1.2.0 | 1.2.4 |