VDB
GCVE-110-NCSC-2025-330
GCVE-110-NCSC-2025-330
Advisory PublishedCVSS 6.4/10
Bouncy Castle for Java and BCPKIX FIPS have a vulnerability allowing excessive resource allocation, while Oracle Communications Cloud Native Core Certificate Management and certain NetApp products face denial of service risks.
Weaknesses (CWE)
CWE-787Out-of-bounds WriteCWE-20Improper Input ValidationCWE-476NULL Pointer DereferenceCWE-407Inefficient Algorithmic ComplexityCWE-400Uncontrolled Resource ConsumptionCWE-129Improper Validation of Array IndexCWE-130Improper Handling of Length Parameter InconsistencyCWE-290Authentication Bypass by SpoofingCWE-674Uncontrolled RecursionCWE-328Use of Weak HashCWE-124Buffer Underwrite ('Buffer Underflow')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-426Untrusted Search PathCWE-125Out-of-bounds ReadCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-1333Inefficient Regular Expression ComplexityCWE-197Numeric Truncation ErrorCWE-241Improper Handling of Unexpected Data TypeCWE-416Use After FreeCWE-147Improper Neutralization of Input TerminatorsCWE-415Double FreeCWE-770Allocation of Resources Without Limits or ThrottlingCWE-252Unchecked Return ValueCWE-789Memory Allocation with Excessive Size ValueCWE-23Relative Path TraversalCWE-385Covert Timing ChannelCWE-918Server-Side Request Forgery (SSRF)CWE-1284Improper Validation of Specified Quantity in InputCWE-440Expected Behavior ViolationCWE-122Heap-based Buffer OverflowCWE-284Improper Access ControlCWE-404Improper Resource Shutdown or ReleaseCWE-121Stack-based Buffer OverflowCWE-94Improper Control of Generation of Code ('Code Injection')CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-253Incorrect Check of Function Return ValueCWE-409Improper Handling of Highly Compressed Data (Data Amplification)
Risk Scores
CVSS 3.1
6.4/10
Medium · CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle | vers:unknown/* | — | — |
Aliases
CVE-2023-26555CVE-2024-12133CVE-2024-28182CVE-2024-35164CVE-2024-37371CVE-2024-47554CVE-2024-50609CVE-2024-51504CVE-2024-57699CVE-2024-7254CVE-2024-8006CVE-2025-1948CVE-2025-25724CVE-2025-27210CVE-2025-27533CVE-2025-27553CVE-2025-27587CVE-2025-27817CVE-2025-32415CVE-2025-32728CVE-2025-32990CVE-2025-3576CVE-2025-4373CVE-2025-4517CVE-2025-4802CVE-2025-48734CVE-2025-48924CVE-2025-48976CVE-2025-48989CVE-2025-49796CVE-2025-5115CVE-2025-52999CVE-2025-5318CVE-2025-53547CVE-2025-53643CVE-2025-53864CVE-2025-5399CVE-2025-54090CVE-2025-55163CVE-2025-57803CVE-2025-58057CVE-2025-5889CVE-2025-59375CVE-2025-6965CVE-2025-7339CVE-2025-7425CVE-2025-7962CVE-2025-8058CVE-2025-8916CVE-2025-9086
References
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.