VDB

GCVE-110-NCSC-2025-129

GCVE-110-NCSC-2025-129
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published April 16, 2025
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Weaknesses (CWE)

CWE-87Improper Neutralization of Alternate XSS SyntaxCWE-404Improper Resource Shutdown or ReleaseCWE-401Missing Release of Memory after Effective LifetimeCWE-73External Control of File Name or PathCWE-400Uncontrolled Resource ConsumptionCWE-125Out-of-bounds ReadCWE-787Out-of-bounds WriteCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-669Incorrect Resource Transfer Between SpheresCWE-284Improper Access ControlCWE-639Authorization Bypass Through User-Controlled KeyCWE-94Improper Control of Generation of Code ('Code Injection')

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Oraclevers:unknown/7.6.0.0.0
Oraclevers:unknown/12.2.1.4.0
Oraclevers:oracle/6.4.0.0.0
Oraclevers:oracle/7.6.0.0.0
Oraclevers:oracle/12.2.1.4.0
Oracle Corporationvers:semver/12.2.1.4.0
Oraclevers:oracle/7.0.0.0.0
Oracle Corporationvers:semver/7.6.0.0.0

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,866 records in the GCVE database · Updated July 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›