VDB

GCVE-110-NCSC-2025-26

GCVE-110-NCSC-2025-26
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published January 22, 2025
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Weaknesses (CWE)

CWE-276Incorrect Default PermissionsCWE-754Improper Check for Unusual or Exceptional ConditionsCWE-328Use of Weak HashCWE-552Files or Directories Accessible to External PartiesCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-354Improper Validation of Integrity Check ValueCWE-400Uncontrolled Resource ConsumptionCWE-222Truncation of Security-relevant InformationCWE-476NULL Pointer DereferenceCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-94Improper Control of Generation of Code ('Code Injection')CWE-122Heap-based Buffer OverflowCWE-601URL Redirection to Untrusted Site ('Open Redirect')

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
oraclejd_edwards_world_security
oraclejd_edwards_enterpriseone_tools
oraclejd_edwards_enterpriseone_orchestrator

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›