<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Linux Bulletin - October 2021 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Linux Bulletin Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>OLBulletinOct2021</ID>
      </Identification>
      <Status>Final</Status>
      <Version>3.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2021-10-19T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
         <Revision>
            <Number>2.0</Number>
            <Date>2021-11-16T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
         <Revision>
            <Number>3.0</Number>
            <Date>2021-12-14T13:00:00-07:00</Date>
            <Description>New CVEs added.</Description>
         </Revision>
      </RevisionHistory>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle Linux security vulnerabilities which have had security patches released for all supported versions and platforms.</Note>
   </DocumentNotes>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/linuxbulletinoct2021.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Linux" Type="Product Family">
            <Branch Name="Oracle Linux OS" Type="Product Name">
               <Branch Name="5" Type="Product Version">
                  <FullProductName ProductID="P-1309V-5">Oracle Linux 5</FullProductName>
               </Branch>
               <Branch Name="6" Type="Product Version">
                  <FullProductName ProductID="P-1309V-6">Oracle Linux 6</FullProductName>
               </Branch>
               <Branch Name="7" Type="Product Version">
                  <FullProductName ProductID="P-1309V-7">Oracle Linux 7</FullProductName>
               </Branch>
               <Branch Name="8" Type="Product Version">
                  <FullProductName ProductID="P-1309V-8">Oracle Linux 8</FullProductName>
               </Branch>
            </Branch>
         </Branch>
     </Branch>
  </ProductTree>
<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1870</Title>
         <Notes>
               <Note Audience="All" Ordinal="1" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. CVSS Base Score: 9.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1870</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-18218</Title>
         <Notes>
               <Note Audience="All" Ordinal="2" Title="Details" Type="Details">This is a vulnerability in  file  in Oracle Linux. cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). CVSS Base Score: 9.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-18218</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4374.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-25014</Title>
         <Notes>
               <Note Audience="All" Ordinal="3" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An unitialized variable is used in function ReadSymbol. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVSS Base Score: 9.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-25014</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30720</Title>
         <Notes>
               <Note Audience="All" Ordinal="4" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted ports on arbitrary servers. CVSS Base Score: 9.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30720</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35942</Title>
         <Notes>
               <Note Audience="All" Ordinal="5" Title="Details" Type="Details">This is a vulnerability in  glibc  in Oracle Linux. The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35942</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4358.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-25009</Title>
         <Notes>
               <Note Audience="All" Ordinal="6" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function WebPMuxCreateInternal. The highest threat from this vulnerability is to data confidentiality and to the service availability. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-25009</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-25010</Title>
         <Notes>
               <Note Audience="All" Ordinal="7" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ApplyFilter. The highest threat from this vulnerability is to data confidentiality and to the service availability. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-25010</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-25012</Title>
         <Notes>
               <Note Audience="All" Ordinal="8" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function WebPMuxCreateInternal. The highest threat from this vulnerability is to data confidentiality and to the service availability. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-25012</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-25013</Title>
         <Notes>
               <Note Audience="All" Ordinal="9" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ShiftBytes. The highest threat from this vulnerability is to data confidentiality and to the service availability. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-25013</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36330</Title>
         <Notes>
               <Note Audience="All" Ordinal="10" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36330</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36331</Title>
         <Notes>
               <Note Audience="All" Ordinal="11" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability. CVSS Base Score: 9.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36331</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20325</Title>
         <Notes>
               <Note Audience="All" Ordinal="12" Title="Details" Type="Details">This is a vulnerability in  httpd:2.4  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20325</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4537.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-13558</Title>
         <Notes>
               <Note Audience="All" Ordinal="13" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-13558</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1788</Title>
         <Notes>
               <Note Audience="All" Ordinal="14" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1788</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1789</Title>
         <Notes>
               <Note Audience="All" Ordinal="15" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1789</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1844</Title>
         <Notes>
               <Note Audience="All" Ordinal="16" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1844</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1871</Title>
         <Notes>
               <Note Audience="All" Ordinal="17" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1871</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-21775</Title>
         <Notes>
               <Note Audience="All" Ordinal="18" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-21775</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-21779</Title>
         <Notes>
               <Note Audience="All" Ordinal="19" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A use-after-free vulnerability exists in the way Webkit's GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-21779</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-21806</Title>
         <Notes>
               <Note Audience="All" Ordinal="20" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.3 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in remote code execution. The victim needs to visit a malicious web site to trigger the vulnerability. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-21806</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30663</Title>
         <Notes>
               <Note Audience="All" Ordinal="21" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30663</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30665</Title>
         <Notes>
               <Note Audience="All" Ordinal="22" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30665</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30734</Title>
         <Notes>
               <Note Audience="All" Ordinal="23" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. ultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30734</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30749</Title>
         <Notes>
               <Note Audience="All" Ordinal="24" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. ultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30749</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30758</Title>
         <Notes>
               <Note Audience="All" Ordinal="25" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30758</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30795</Title>
         <Notes>
               <Note Audience="All" Ordinal="26" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30795</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30797</Title>
         <Notes>
               <Note Audience="All" Ordinal="27" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. This issue was addressed with improved checks. This issue is fixed in iOS 14.7, Safari 14.1.2, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7. Processing maliciously crafted web content may lead to code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30797</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30799</Title>
         <Notes>
               <Note Audience="All" Ordinal="28" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. ultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30799</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3653</Title>
         <Notes>
               <Note Audience="All" Ordinal="29" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. A flaw was found in the KVM&#39;s AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the &quot;int_ctl&quot; field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kernel versions prior to 5.14-rc7. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3653</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9564.html</URL>
                  <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3656</Title>
         <Notes>
               <Note Audience="All" Ordinal="30" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3656</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9564.html</URL>
                  <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3653</Title>
         <Notes>
               <Note Audience="All" Ordinal="31" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel-container  in Oracle Linux. A flaw was found in the KVM&#39;s AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the &quot;int_ctl&quot; field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kernel versions prior to 5.14-rc7. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3653</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3656</Title>
         <Notes>
               <Note Audience="All" Ordinal="32" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel-container  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3656</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43537</Title>
         <Notes>
               <Note Audience="All" Ordinal="33" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43537</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43537</Title>
         <Notes>
               <Note Audience="All" Ordinal="34" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43537</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43539</Title>
         <Notes>
               <Note Audience="All" Ordinal="35" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43539</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43539</Title>
         <Notes>
               <Note Audience="All" Ordinal="36" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43539</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-41159</Title>
         <Notes>
               <Note Audience="All" Ordinal="37" Title="Details" Type="Details">This is a vulnerability in  freerdp  in Oracle Linux. FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (/gt:rpc) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unable to update then use /gt:http rather than /gt:rdp connections if possible or use a direct connection without a gateway. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-41159</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4622.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-41160</Title>
         <Notes>
               <Note Audience="All" Ordinal="38" Title="Details" Type="Details">This is a vulnerability in  freerdp  in Oracle Linux. FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send 0 width/height or out of bound rectangles to trigger out of bound writes. With 0 width or heigth the memory allocation will be 0 but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-41160</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4622.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36158</Title>
         <Notes>
               <Note Audience="All" Ordinal="39" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36158</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28091</Title>
         <Notes>
               <Note Audience="All" Ordinal="40" Title="Details" Type="Details">This is a vulnerability in  lasso  in Oracle Linux. Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28091</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4325.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-17541</Title>
         <Notes>
               <Note Audience="All" Ordinal="41" Title="Details" Type="Details">This is a vulnerability in  libjpeg-turbo  in Oracle Linux. Libjpeg-turbo all version have a stack-based buffer overflow in the &quot;transform&quot; component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-17541</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4288.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2016-6893</Title>
         <Notes>
               <Note Audience="All" Ordinal="42" Title="Details" Type="Details">This is a vulnerability in  mailman  in Oracle Linux. Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim&#39;s account. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2016-6893</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4913.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43527</Title>
         <Notes>
               <Note Audience="All" Ordinal="43" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43527</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4903.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43527</Title>
         <Notes>
               <Note Audience="All" Ordinal="44" Title="Details" Type="Details">This is a vulnerability in  nss  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43527</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4904.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-20847</Title>
         <Notes>
               <Note Audience="All" Ordinal="45" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-20847</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-5827</Title>
         <Notes>
               <Note Audience="All" Ordinal="46" Title="Details" Type="Details">This is a vulnerability in  sqlite  in Oracle Linux. Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-5827</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4396.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43537</Title>
         <Notes>
               <Note Audience="All" Ordinal="47" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43537</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43537</Title>
         <Notes>
               <Note Audience="All" Ordinal="48" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43537</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43539</Title>
         <Notes>
               <Note Audience="All" Ordinal="49" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43539</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43539</Title>
         <Notes>
               <Note Audience="All" Ordinal="50" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43539</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="51" Title="Details" Type="Details">This is a vulnerability in  annobin  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4593.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="52" Title="Details" Type="Details">This is a vulnerability in  binutils  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4595.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="53" Title="Details" Type="Details">This is a vulnerability in  gcc  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4587.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="54" Title="Details" Type="Details">This is a vulnerability in  gcc-toolset-10-annobin  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4592.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="55" Title="Details" Type="Details">This is a vulnerability in  gcc-toolset-10-binutils  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4649.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="56" Title="Details" Type="Details">This is a vulnerability in  gcc-toolset-10-gcc  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4585.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="57" Title="Details" Type="Details">This is a vulnerability in  gcc-toolset-11-annobin  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4591.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="58" Title="Details" Type="Details">This is a vulnerability in  gcc-toolset-11-binutils  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4594.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="59" Title="Details" Type="Details">This is a vulnerability in  gcc-toolset-11-gcc  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4586.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="60" Title="Details" Type="Details">This is a vulnerability in  llvm-toolset:ol8  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4743.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42574</Title>
         <Notes>
               <Note Audience="All" Ordinal="61" Title="Details" Type="Details">This is a vulnerability in  rust-toolset:ol8  in Oracle Linux. An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. CVSS Base Score: 8.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4590.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24870</Title>
         <Notes>
               <Note Audience="All" Ordinal="62" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. Libraw before 0.20.1 has a stack buffer overflow via LibRaw::identify_process_dng_fields in identify.cpp. CVSS Base Score: 8.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24870</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30689</Title>
         <Notes>
               <Note Audience="All" Ordinal="63" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A logic issue was addressed with improved state management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting. CVSS Base Score: 8.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30689</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30744</Title>
         <Notes>
               <Note Audience="All" Ordinal="64" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting. CVSS Base Score: 8.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30744</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43267</Title>
         <Notes>
               <Note Audience="All" Ordinal="65" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. CVSS Base Score: 8.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43267</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4647.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31535</Title>
         <Notes>
               <Note Audience="All" Ordinal="66" Title="Details" Type="Details">This is a vulnerability in  libX11  in Oracle Linux. LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the maximum size allowed by the protocol (and also longer than the maximum packet size for normal-sized packets). The user-controlled data exceeding the maximum size is then interpreted by the server as additional X protocol requests and executed, e.g., to disable X server authorization completely. For example, if the victim encounters malicious terminal control sequences for color codes, then the attacker may be able to take full control of the running graphical session. CVSS Base Score: 8.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31535</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4326.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42097</Title>
         <Notes>
               <Note Audience="All" Ordinal="67" Title="Details" Type="Details">This is a vulnerability in  mailman  in Oracle Linux. GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover). CVSS Base Score: 8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42097</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4913.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-44227</Title>
         <Notes>
               <Note Audience="All" Ordinal="68" Title="Details" Type="Details">This is a vulnerability in  mailman  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-44227</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4913.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42097</Title>
         <Notes>
               <Note Audience="All" Ordinal="69" Title="Details" Type="Details">This is a vulnerability in  mailman:2.1  in Oracle Linux. GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover). CVSS Base Score: 8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42097</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4826.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-44227</Title>
         <Notes>
               <Note Audience="All" Ordinal="70" Title="Details" Type="Details">This is a vulnerability in  mailman:2.1  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-44227</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4916.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27918</Title>
         <Notes>
               <Note Audience="All" Ordinal="71" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27918</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20095</Title>
         <Notes>
               <Note Audience="All" Ordinal="72" Title="Details" Type="Details">This is a vulnerability in  babel  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20095</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4201.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42771</Title>
         <Notes>
               <Note Audience="All" Ordinal="73" Title="Details" Type="Details">This is a vulnerability in  babel  in Oracle Linux. Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42771</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4201.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-18032</Title>
         <Notes>
               <Note Audience="All" Ordinal="74" Title="Details" Type="Details">This is a vulnerability in  graphviz  in Oracle Linux. Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the &quot;lib/common/shapes.c&quot; component. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-18032</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4256.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27828</Title>
         <Notes>
               <Note Audience="All" Ordinal="75" Title="Details" Type="Details">This is a vulnerability in  jasper  in Oracle Linux. There&#39;s a flaw in jasper&#39;s jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27828</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4235.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-12762</Title>
         <Notes>
               <Note Audience="All" Ordinal="76" Title="Details" Type="Details">This is a vulnerability in  json-c  in Oracle Linux. json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-12762</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4382.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36385</Title>
         <Notes>
               <Note Audience="All" Ordinal="77" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36385</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4777.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33200</Title>
         <Notes>
               <Note Audience="All" Ordinal="78" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off reg causes a masking direction change, which then results in an incorrect final aux-&gt;alu_limit. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33200</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3489</Title>
         <Notes>
               <Note Audience="All" Ordinal="79" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee (&quot;bpf, ringbuf: Deny reserve of buffers larger than ringbuf&quot;) (v5.13-rc4) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. It was introduced via 457f44363a88 (&quot;bpf: Implement BPF ring buffer and verifier support for it&quot;) (v5.8-rc1). CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3489</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3600</Title>
         <Notes>
               <Note Audience="All" Ordinal="80" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3600</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-35523</Title>
         <Notes>
               <Note Audience="All" Ordinal="81" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle Linux. An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-35523</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4241.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-35524</Title>
         <Notes>
               <Note Audience="All" Ordinal="82" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle Linux. A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff&#39;s TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-35524</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4241.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27814</Title>
         <Notes>
               <Note Audience="All" Ordinal="83" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash or in some cases execute arbitrary code with the permission of the user running such an application. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27814</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27823</Title>
         <Notes>
               <Note Audience="All" Ordinal="84" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. A flaw was found in OpenJPEGs encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27823</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20095</Title>
         <Notes>
               <Note Audience="All" Ordinal="85" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20095</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42771</Title>
         <Notes>
               <Note Audience="All" Ordinal="86" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42771</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20095</Title>
         <Notes>
               <Note Audience="All" Ordinal="87" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20095</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42771</Title>
         <Notes>
               <Note Audience="All" Ordinal="88" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42771</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-1946</Title>
         <Notes>
               <Note Audience="All" Ordinal="89" Title="Details" Type="Details">This is a vulnerability in  spamassassin  in Oracle Linux. In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files from trusted places. CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-1946</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4315.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3778</Title>
         <Notes>
               <Note Audience="All" Ordinal="90" Title="Details" Type="Details">This is a vulnerability in  vim  in Oracle Linux. vim is vulnerable to Heap-based Buffer Overflow CVSS Base Score: 7.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3778</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4517.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31292</Title>
         <Notes>
               <Note Audience="All" Ordinal="91" Title="Details" Type="Details">This is a vulnerability in  compat-exiv2-026  in Oracle Linux. An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31292</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4319.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3580</Title>
         <Notes>
               <Note Audience="All" Ordinal="92" Title="Details" Type="Details">This is a vulnerability in  gnutls and nettle  in Oracle Linux. A flaw was found in the way nettle&#39;s RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3580</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4451.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-27358</Title>
         <Notes>
               <Note Audience="All" Ordinal="93" Title="Details" Type="Details">This is a vulnerability in  grafana  in Oracle Linux. The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-27358</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4226.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33195</Title>
         <Notes>
               <Note Audience="All" Ordinal="94" Title="Details" Type="Details">This is a vulnerability in  grafana  in Oracle Linux. Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33195</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4226.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33197</Title>
         <Notes>
               <Note Audience="All" Ordinal="95" Title="Details" Type="Details">This is a vulnerability in  grafana  in Oracle Linux. In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33197</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4226.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-39365</Title>
         <Notes>
               <Note Audience="All" Ordinal="96" Title="Details" Type="Details">This is a vulnerability in  grilo  in Oracle Linux. In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-39365</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4339.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-26690</Title>
         <Notes>
               <Note Audience="All" Ordinal="97" Title="Details" Type="Details">This is a vulnerability in  httpd:2.4  in Oracle Linux. Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-26690</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4257.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33560</Title>
         <Notes>
               <Note Audience="All" Ordinal="98" Title="Details" Type="Details">This is a vulnerability in  libgcrypt  in Oracle Linux. Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33560</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4409.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36332</Title>
         <Notes>
               <Note Audience="All" Ordinal="99" Title="Details" Type="Details">This is a vulnerability in  libwebp  in Oracle Linux. A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36332</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4231.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3575</Title>
         <Notes>
               <Note Audience="All" Ordinal="100" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3575</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-23840</Title>
         <Notes>
               <Note Audience="All" Ordinal="101" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x). CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-23840</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4424.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-21702</Title>
         <Notes>
               <Note Audience="All" Ordinal="102" Title="Details" Type="Details">This is a vulnerability in  php:7.4  in Oracle Linux. In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-21702</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4213.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-18874</Title>
         <Notes>
               <Note Audience="All" Ordinal="103" Title="Details" Type="Details">This is a vulnerability in  python-psutil  in Oracle Linux. psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-18874</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4324.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27619</Title>
         <Notes>
               <Note Audience="All" Ordinal="104" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27619</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-28493</Title>
         <Notes>
               <Note Audience="All" Ordinal="105" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-28493</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20270</Title>
         <Notes>
               <Note Audience="All" Ordinal="106" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the &quot;exception&quot; keyword. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20270</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-27291</Title>
         <Notes>
               <Note Audience="All" Ordinal="107" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-27291</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20270</Title>
         <Notes>
               <Note Audience="All" Ordinal="108" Title="Details" Type="Details">This is a vulnerability in  python36:3.6  in Oracle Linux. An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the &quot;exception&quot; keyword. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20270</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4150.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-27291</Title>
         <Notes>
               <Note Audience="All" Ordinal="109" Title="Details" Type="Details">This is a vulnerability in  python36:3.6  in Oracle Linux. In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-27291</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4150.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-18874</Title>
         <Notes>
               <Note Audience="All" Ordinal="110" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-18874</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-28493</Title>
         <Notes>
               <Note Audience="All" Ordinal="111" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-28493</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33503</Title>
         <Notes>
               <Note Audience="All" Ordinal="112" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33503</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33503</Title>
         <Notes>
               <Note Audience="All" Ordinal="113" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33503</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-19603</Title>
         <Notes>
               <Note Audience="All" Ordinal="114" Title="Details" Type="Details">This is a vulnerability in  sqlite  in Oracle Linux. SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-19603</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4396.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-8037</Title>
         <Notes>
               <Note Audience="All" Ordinal="115" Title="Details" Type="Details">This is a vulnerability in  tcpdump  in Oracle Linux. The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. CVSS Base Score: 7.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-8037</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4236.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-29368</Title>
         <Notes>
               <Note Audience="All" Ordinal="116" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1. CVSS Base Score: 7.4 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-29368</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.4</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29921</Title>
         <Notes>
               <Note Audience="All" Ordinal="117" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. CVSS Base Score: 7.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29921</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29921</Title>
         <Notes>
               <Note Audience="All" Ordinal="118" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. CVSS Base Score: 7.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29921</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28651</Title>
         <Notes>
               <Note Audience="All" Ordinal="119" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption. CVSS Base Score: 7.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28651</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29922</Title>
         <Notes>
               <Note Audience="All" Ordinal="120" Title="Details" Type="Details">This is a vulnerability in  rust-toolset:ol8  in Oracle Linux. library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. CVSS Base Score: 7.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29922</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4270.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3571</Title>
         <Notes>
               <Note Audience="All" Ordinal="121" Title="Details" Type="Details">This is a vulnerability in  linuxptp  in Oracle Linux. A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw affects linuxptp versions before 3.1.1 and before 2.0.1. CVSS Base Score: 7.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3571</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4321.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20194</Title>
         <Notes>
               <Note Audience="All" Ordinal="122" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_getsockopt() function that can lead to heap overflow (because of non-hardened usercopy). The impact of attack could be deny of service or possibly privileges escalation. CVSS Base Score: 7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20194</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-23133</Title>
         <Notes>
               <Note Audience="All" Ordinal="123" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(sk)-&gt;sctp.addr_wq_lock then an element is removed from the auto_asconf_splist list without any proper locking. This can be exploited by an attacker with network service privileges to escalate to root or from the context of an unprivileged user directly if a BPF_CGROUP_INET_SOCK_CREATE is attached which denies creation of some SCTP socket. CVSS Base Score: 7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-23133</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31440</Title>
         <Notes>
               <Note Audience="All" Ordinal="124" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of eBPF programs. The issue results from the lack of proper validation of user-supplied eBPF programs prior to executing them. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel. Was ZDI-CAN-13661. CVSS Base Score: 7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31440</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-41617</Title>
         <Notes>
               <Note Audience="All" Ordinal="125" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user. CVSS Base Score: 7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-41617</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4782.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35567</Title>
         <Notes>
               <Note Audience="All" Ordinal="126" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35567</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28652</Title>
         <Notes>
               <Note Audience="All" Ordinal="127" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cache Manager API access privilege. CVSS Base Score: 6.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28652</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27777</Title>
         <Notes>
               <Note Audience="All" Ordinal="128" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel. CVSS Base Score: 6.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27777</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36386</Title>
         <Notes>
               <Note Audience="All" Ordinal="129" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. CVSS Base Score: 6.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36386</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31916</Title>
         <Notes>
               <Note Audience="All" Ordinal="130" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. CVSS Base Score: 6.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31916</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3573</Title>
         <Notes>
               <Note Audience="All" Ordinal="131" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local user could use this flaw to crash the system or escalate their privileges on the system. This flaw affects the Linux kernel versions prior to 5.13-rc5. CVSS Base Score: 6.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3573</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20271</Title>
         <Notes>
               <Note Audience="All" Ordinal="132" Title="Details" Type="Details">This is a vulnerability in  rpm  in Oracle Linux. A flaw was found in RPM&#39;s signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability. CVSS Base Score: 6.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20271</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4785.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1765</Title>
         <Notes>
               <Note Audience="All" Ordinal="133" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted web content may violate iframe sandboxing policy. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1765</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1799</Title>
         <Notes>
               <Note Audience="All" Ordinal="134" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. A malicious website may be able to access restricted ports on arbitrary servers. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1799</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-1801</Title>
         <Notes>
               <Note Audience="All" Ordinal="135" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Maliciously crafted web content may violate iframe sandboxing policy. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-1801</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30682</Title>
         <Notes>
               <Note Audience="All" Ordinal="136" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30682</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-25214</Title>
         <Notes>
               <Note Audience="All" Ordinal="137" Title="Details" Type="Details">This is a vulnerability in  bind  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-25214</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4384.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3487</Title>
         <Notes>
               <Note Audience="All" Ordinal="138" Title="Details" Type="Details">This is a vulnerability in  binutils  in Oracle Linux. There&#39;s a flaw in the BFD library of binutils in versions before 2.36. An attacker who supplies a crafted file to an application linked with BFD, and using the DWARF functionality, could cause an impact to system availability by way of excessive memory consumption. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3487</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4364.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20291</Title>
         <Notes>
               <Note Audience="All" Ordinal="139" Title="Details" Type="Details">This is a vulnerability in  container-tools:ol8  in Oracle Linux. A deadlock vulnerability was found in &#39;github.com/containers/storage&#39; in versions before 1.28.1. When a container image is processed, each layer is unpacked using tar. If one of those layers is not a valid tar archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS). CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20291</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4154.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43536</Title>
         <Notes>
               <Note Audience="All" Ordinal="140" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43536</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43536</Title>
         <Notes>
               <Note Audience="All" Ordinal="141" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43536</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43541</Title>
         <Notes>
               <Note Audience="All" Ordinal="142" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43541</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43541</Title>
         <Notes>
               <Note Audience="All" Ordinal="143" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43541</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43542</Title>
         <Notes>
               <Note Audience="All" Ordinal="144" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43542</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43542</Title>
         <Notes>
               <Note Audience="All" Ordinal="145" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43542</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3114</Title>
         <Notes>
               <Note Audience="All" Ordinal="146" Title="Details" Type="Details">This is a vulnerability in  grafana  in Oracle Linux. In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3114</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4226.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-34558</Title>
         <Notes>
               <Note Audience="All" Ordinal="147" Title="Details" Type="Details">This is a vulnerability in  grafana  in Oracle Linux. The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-34558</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4226.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26140</Title>
         <Notes>
               <Note Audience="All" Ordinal="148" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26140</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26141</Title>
         <Notes>
               <Note Audience="All" Ordinal="149" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26141</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26143</Title>
         <Notes>
               <Note Audience="All" Ordinal="150" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26143</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26144</Title>
         <Notes>
               <Note Audience="All" Ordinal="151" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26144</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26145</Title>
         <Notes>
               <Note Audience="All" Ordinal="152" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26145</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-37750</Title>
         <Notes>
               <Note Audience="All" Ordinal="153" Title="Details" Type="Details">This is a vulnerability in  krb5  in Oracle Linux. The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-37750</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4788.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-20845</Title>
         <Notes>
               <Note Audience="All" Ordinal="154" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-20845</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-5727</Title>
         <Notes>
               <Note Audience="All" Ordinal="155" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-5727</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-5785</Title>
         <Notes>
               <Note Audience="All" Ordinal="156" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-5785</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-15389</Title>
         <Notes>
               <Note Audience="All" Ordinal="157" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-15389</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-7069</Title>
         <Notes>
               <Note Audience="All" Ordinal="158" Title="Details" Type="Details">This is a vulnerability in  php:7.4  in Oracle Linux. In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-7069</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4213.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3733</Title>
         <Notes>
               <Note Audience="All" Ordinal="159" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3733</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3737</Title>
         <Notes>
               <Note Audience="All" Ordinal="160" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3737</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-13750</Title>
         <Notes>
               <Note Audience="All" Ordinal="161" Title="Details" Type="Details">This is a vulnerability in  sqlite  in Oracle Linux. Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-13750</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4396.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-13751</Title>
         <Notes>
               <Note Audience="All" Ordinal="162" Title="Details" Type="Details">This is a vulnerability in  sqlite  in Oracle Linux. Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-13751</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4396.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28662</Title>
         <Notes>
               <Note Audience="All" Ordinal="163" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28662</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31806</Title>
         <Notes>
               <Note Audience="All" Ordinal="164" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31806</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31807</Title>
         <Notes>
               <Note Audience="All" Ordinal="165" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31807</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31808</Title>
         <Notes>
               <Note Audience="All" Ordinal="166" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31808</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33620</Title>
         <Notes>
               <Note Audience="All" Ordinal="167" Title="Details" Type="Details">This is a vulnerability in  squid:4  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33620</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4292.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43536</Title>
         <Notes>
               <Note Audience="All" Ordinal="168" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43536</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43536</Title>
         <Notes>
               <Note Audience="All" Ordinal="169" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43536</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43541</Title>
         <Notes>
               <Note Audience="All" Ordinal="170" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43541</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43541</Title>
         <Notes>
               <Note Audience="All" Ordinal="171" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43541</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43542</Title>
         <Notes>
               <Note Audience="All" Ordinal="172" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43542</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43542</Title>
         <Notes>
               <Note Audience="All" Ordinal="173" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43542</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3667</Title>
         <Notes>
               <Note Audience="All" Ordinal="174" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3667</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3445</Title>
         <Notes>
               <Note Audience="All" Ordinal="175" Title="Details" Type="Details">This is a vulnerability in  dnf  in Oracle Linux. A flaw was found in libdnf&#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. CVSS Base Score: 6.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3445</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4464.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43528</Title>
         <Notes>
               <Note Audience="All" Ordinal="176" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43528</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43528</Title>
         <Notes>
               <Note Audience="All" Ordinal="177" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43528</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28950</Title>
         <Notes>
               <Note Audience="All" Ordinal="178" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A &quot;stall on CPU&quot; can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1. CVSS Base Score: 6.2 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28950</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29646</Title>
         <Notes>
               <Note Audience="All" Ordinal="179" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8. CVSS Base Score: 6.2 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29646</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-31829</Title>
         <Notes>
               <Note Audience="All" Ordinal="180" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel. CVSS Base Score: 6.2 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-31829</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29338</Title>
         <Notes>
               <Note Audience="All" Ordinal="181" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option &quot;-ImgDir&quot; on a directory that contains 1048576 files. CVSS Base Score: 6.2 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29338</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.2</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-13529</Title>
         <Notes>
               <Note Audience="All" Ordinal="182" Title="Details" Type="Details">This is a vulnerability in  NetworkManager  in Oracle Linux. An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-13529</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4361.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43543</Title>
         <Notes>
               <Note Audience="All" Ordinal="183" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43543</Title>
         <Notes>
               <Note Audience="All" Ordinal="184" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28957</Title>
         <Notes>
               <Note Audience="All" Ordinal="185" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. An XSS vulnerability was discovered in python-lxml&#39;s clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28957</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28957</Title>
         <Notes>
               <Note Audience="All" Ordinal="186" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. An XSS vulnerability was discovered in python-lxml&#39;s clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28957</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28957</Title>
         <Notes>
               <Note Audience="All" Ordinal="187" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. An XSS vulnerability was discovered in python-lxml&#39;s clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the Cleaner class does not remove the formaction attribute allowing for JS to bypass the sanitizer. A remote attacker could exploit this flaw to run arbitrary JS code on users who interact with incorrectly sanitized HTML. This issue is patched in lxml 4.6.3. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28957</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43543</Title>
         <Notes>
               <Note Audience="All" Ordinal="188" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43543</Title>
         <Notes>
               <Note Audience="All" Ordinal="189" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43543</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3796</Title>
         <Notes>
               <Note Audience="All" Ordinal="190" Title="Details" Type="Details">This is a vulnerability in  vim  in Oracle Linux. vim is vulnerable to Use After Free CVSS Base Score: 6.1 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3796</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>6.1</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4517.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-33574</Title>
         <Notes>
               <Note Audience="All" Ordinal="191" Title="Details" Type="Details">This is a vulnerability in  glibc  in Oracle Linux. The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact. CVSS Base Score: 5.9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-33574</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4358.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-30641</Title>
         <Notes>
               <Note Audience="All" Ordinal="192" Title="Details" Type="Details">This is a vulnerability in  httpd:2.4  in Oracle Linux. Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with &#39;MergeSlashes OFF&#39; CVSS Base Score: 5.9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-30641</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4257.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-16135</Title>
         <Notes>
               <Note Audience="All" Ordinal="193" Title="Details" Type="Details">This is a vulnerability in  libssh  in Oracle Linux. libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL. CVSS Base Score: 5.9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-16135</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4387.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-23841</Title>
         <Notes>
               <Note Audience="All" Ordinal="194" Title="Details" Type="Details">This is a vulnerability in  openssl  in Oracle Linux. The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x). CVSS Base Score: 5.9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-23841</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4424.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-23336</Title>
         <Notes>
               <Note Audience="All" Ordinal="195" Title="Details" Type="Details">This is a vulnerability in  python27:2.7  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-23336</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4151.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-23336</Title>
         <Notes>
               <Note Audience="All" Ordinal="196" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.9 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-23336</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.9</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-0129</Title>
         <Notes>
               <Note Audience="All" Ordinal="197" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. CVSS Base Score: 5.7 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-0129</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.7</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3426</Title>
         <Notes>
               <Note Audience="All" Ordinal="198" Title="Details" Type="Details">This is a vulnerability in  python3  in Oracle Linux. There&#39;s a flaw in Python 3&#39;s pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7. CVSS Base Score: 5.7 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3426</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.7</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4399.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3426</Title>
         <Notes>
               <Note Audience="All" Ordinal="199" Title="Details" Type="Details">This is a vulnerability in  python3  in Oracle Linux. There&#39;s a flaw in Python 3&#39;s pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7. CVSS Base Score: 5.7 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3426</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.7</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9562.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3426</Title>
         <Notes>
               <Note Audience="All" Ordinal="200" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. There&#39;s a flaw in Python 3&#39;s pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7. CVSS Base Score: 5.7 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3426</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.7</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3426</Title>
         <Notes>
               <Note Audience="All" Ordinal="201" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. There&#39;s a flaw in Python 3&#39;s pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7. CVSS Base Score: 5.7 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3426</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.7</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3602</Title>
         <Notes>
               <Note Audience="All" Ordinal="202" Title="Details" Type="Details">This is a vulnerability in  container-tools:3.0  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.6 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3602</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4222.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3602</Title>
         <Notes>
               <Note Audience="All" Ordinal="203" Title="Details" Type="Details">This is a vulnerability in  container-tools:ol8  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.6 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3602</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4154.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3602</Title>
         <Notes>
               <Note Audience="All" Ordinal="204" Title="Details" Type="Details">This is a vulnerability in container-tools:2.0  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.6 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3602</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.6</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4221.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3744</Title>
         <Notes>
               <Note Audience="All" Ordinal="205" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3744</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9564.html</URL>
                  <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3744</Title>
         <Notes>
               <Note Audience="All" Ordinal="206" Title="Details" Type="Details">This is a vulnerability in  Unbreakable Enterprise kernel-container  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3744</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-9565.html</URL>
                  <ProductID>P-1309V-7</ProductID>
               <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-10001</Title>
         <Notes>
               <Note Audience="All" Ordinal="207" Title="Details" Type="Details">This is a vulnerability in  cups  in Oracle Linux. An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-10001</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4393.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2018-20673</Title>
         <Notes>
               <Note Audience="All" Ordinal="208" Title="Details" Type="Details">This is a vulnerability in  gcc  in Oracle Linux. The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for &quot;Create an array for saving the template argument values&quot;) that can trigger a heap-based buffer overflow, as demonstrated by nm. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2018-20673</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4386.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-26926</Title>
         <Notes>
               <Note Audience="All" Ordinal="209" Title="Details" Type="Details">This is a vulnerability in  jasper  in Oracle Linux. A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-26926</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4235.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-26927</Title>
         <Notes>
               <Note Audience="All" Ordinal="210" Title="Details" Type="Details">This is a vulnerability in  jasper  in Oracle Linux. A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-26927</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4235.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3272</Title>
         <Notes>
               <Note Audience="All" Ordinal="211" Title="Details" Type="Details">This is a vulnerability in  jasper  in Oracle Linux. jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3272</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4235.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-0427</Title>
         <Notes>
               <Note Audience="All" Ordinal="212" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171 CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-0427</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24502</Title>
         <Notes>
               <Note Audience="All" Ordinal="213" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24502</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24503</Title>
         <Notes>
               <Note Audience="All" Ordinal="214" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24503</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24504</Title>
         <Notes>
               <Note Audience="All" Ordinal="215" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24504</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29650</Title>
         <Notes>
               <Note Audience="All" Ordinal="216" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of a new table value, aka CID-175e476b8cdf. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29650</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3659</Title>
         <Notes>
               <Note Audience="All" Ordinal="217" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3659</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3679</Title>
         <Notes>
               <Note Audience="All" Ordinal="218" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3679</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-35521</Title>
         <Notes>
               <Note Audience="All" Ordinal="219" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle Linux. A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-35521</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4241.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-35522</Title>
         <Notes>
               <Note Audience="All" Ordinal="220" Title="Details" Type="Details">This is a vulnerability in  libtiff  in Oracle Linux. In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-35522</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4241.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-12973</Title>
         <Notes>
               <Note Audience="All" Ordinal="221" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-12973</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27824</Title>
         <Notes>
               <Note Audience="All" Ordinal="222" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. A flaw was found in OpenJPEGs encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27824</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27842</Title>
         <Notes>
               <Note Audience="All" Ordinal="223" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. There&#39;s a flaw in openjpeg&#39;s t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27842</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27843</Title>
         <Notes>
               <Note Audience="All" Ordinal="224" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27843</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-27845</Title>
         <Notes>
               <Note Audience="All" Ordinal="225" Title="Details" Type="Details">This is a vulnerability in  openjpeg2  in Oracle Linux. There&#39;s a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg&#39;s conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-27845</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4251.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-13435</Title>
         <Notes>
               <Note Audience="All" Ordinal="226" Title="Details" Type="Details">This is a vulnerability in  sqlite  in Oracle Linux. SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c. CVSS Base Score: 5.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-13435</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4396.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43546</Title>
         <Notes>
               <Note Audience="All" Ordinal="227" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43546</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43546</Title>
         <Notes>
               <Note Audience="All" Ordinal="228" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43546</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-17595</Title>
         <Notes>
               <Note Audience="All" Ordinal="229" Title="Details" Type="Details">This is a vulnerability in  ncurses  in Oracle Linux. There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012. CVSS Base Score: 5.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-17595</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4426.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43546</Title>
         <Notes>
               <Note Audience="All" Ordinal="230" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43546</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43546</Title>
         <Notes>
               <Note Audience="All" Ordinal="231" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.4 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43546</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.4</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28153</Title>
         <Notes>
               <Note Audience="All" Ordinal="232" Title="Details" Type="Details">This is a vulnerability in  glib2  in Oracle Linux. An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.) CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28153</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4385.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35556</Title>
         <Notes>
               <Note Audience="All" Ordinal="233" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35556</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35559</Title>
         <Notes>
               <Note Audience="All" Ordinal="234" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35559</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35561</Title>
         <Notes>
               <Note Audience="All" Ordinal="235" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35561</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35564</Title>
         <Notes>
               <Note Audience="All" Ordinal="236" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35564</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35578</Title>
         <Notes>
               <Note Audience="All" Ordinal="237" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35578</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35586</Title>
         <Notes>
               <Note Audience="All" Ordinal="238" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35586</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24370</Title>
         <Notes>
               <Note Audience="All" Ordinal="239" Title="Details" Type="Details">This is a vulnerability in  lua  in Oracle Linux. ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31). CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24370</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4510.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-17594</Title>
         <Notes>
               <Note Audience="All" Ordinal="240" Title="Details" Type="Details">This is a vulnerability in  ncurses  in Oracle Linux. There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-17594</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4426.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-14155</Title>
         <Notes>
               <Note Audience="All" Ordinal="241" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-14155</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4373.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-7070</Title>
         <Notes>
               <Note Audience="All" Ordinal="242" Title="Details" Type="Details">This is a vulnerability in  php:7.4  in Oracle Linux. In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-7070</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4213.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-7071</Title>
         <Notes>
               <Note Audience="All" Ordinal="243" Title="Details" Type="Details">This is a vulnerability in  php:7.4  in Oracle Linux. In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var(, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL. CVSS Base Score: 5.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-7071</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4213.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28971</Title>
         <Notes>
               <Note Audience="All" Ordinal="244" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6. CVSS Base Score: 5.1 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28971</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3348</Title>
         <Notes>
               <Note Audience="All" Ordinal="245" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3d71. CVSS Base Score: 5.1 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3348</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>5.1</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26146</Title>
         <Notes>
               <Note Audience="All" Ordinal="246" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design. CVSS Base Score: 4.8 CVSS V3 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26146</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.8</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26147</Title>
         <Notes>
               <Note Audience="All" Ordinal="247" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. CVSS Base Score: 4.8 CVSS V3 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26147</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.8</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2019-20838</Title>
         <Notes>
               <Note Audience="All" Ordinal="248" Title="Details" Type="Details">This is a vulnerability in  pcre  in Oracle Linux. libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454. CVSS Base Score: 4.8 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2019-20838</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.8</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4373.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20284</Title>
         <Notes>
               <Note Audience="All" Ordinal="249" Title="Details" Type="Details">This is a vulnerability in  binutils  in Oracle Linux. A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20284</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4364.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-37618</Title>
         <Notes>
               <Note Audience="All" Ordinal="250" Title="Details" Type="Details">This is a vulnerability in  compat-exiv2-026  in Oracle Linux. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when printing the image ICC profile, which is a less frequently used Exiv2 operation that requires an extra command line option (-p C). The bug is fixed in version v0.27.5. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-37618</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4319.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-37619</Title>
         <Notes>
               <Note Audience="All" Ordinal="251" Title="Details" Type="Details">This is a vulnerability in  compat-exiv2-026  in Oracle Linux. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service by crashing Exiv2, if they can trick the victim into running Exiv2 on a crafted image file. Note that this bug is only triggered when writing the metadata, which is a less frequently used Exiv2 operation than reading the metadata. For example, to trigger the bug in the Exiv2 command-line application, you need to add an extra command-line argument such as insert. The bug is fixed in version v0.27.5. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-37619</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4319.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3800</Title>
         <Notes>
               <Note Audience="All" Ordinal="252" Title="Details" Type="Details">This is a vulnerability in  glib2  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3800</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4385.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="253" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3564</Title>
         <Notes>
               <Note Audience="All" Ordinal="253" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3564</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="254" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20269</Title>
         <Notes>
               <Note Audience="All" Ordinal="254" Title="Details" Type="Details">This is a vulnerability in  kexec-tools  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.7 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20269</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.7</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4404.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="255" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3572</Title>
         <Notes>
               <Note Audience="All" Ordinal="255" Title="Details" Type="Details">This is a vulnerability in  python-pip  in Oracle Linux. A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1. CVSS Base Score: 4.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3572</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4455.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="256" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3572</Title>
         <Notes>
               <Note Audience="All" Ordinal="256" Title="Details" Type="Details">This is a vulnerability in  python38:3.8 and python38-devel:3.8  in Oracle Linux. A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1. CVSS Base Score: 4.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3572</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4162.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="257" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3572</Title>
         <Notes>
               <Note Audience="All" Ordinal="257" Title="Details" Type="Details">This is a vulnerability in  python39:3.9 and python39-devel:3.9  in Oracle Linux. A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1. CVSS Base Score: 4.5 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3572</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.5</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4160.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="258" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20317</Title>
         <Notes>
               <Note Audience="All" Ordinal="258" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP. CVSS Base Score: 4.4 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20317</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.4</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4647.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="259" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-29660</Title>
         <Notes>
               <Note Audience="All" Ordinal="259" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. CVSS Base Score: 4.4 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-29660</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.4</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="260" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-29155</Title>
         <Notes>
               <Note Audience="All" Ordinal="260" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modification performed by the first operation is not correctly accounted for when restricting subsequent operations. CVSS Base Score: 4.4 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-29155</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.4</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="261" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3565</Title>
         <Notes>
               <Note Audience="All" Ordinal="261" Title="Details" Type="Details">This is a vulnerability in  tpm2-tools  in Oracle Linux. A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality. CVSS Base Score: 4.4 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3565</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.4</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4413.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="262" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43538</Title>
         <Notes>
               <Note Audience="All" Ordinal="262" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43538</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="263" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43538</Title>
         <Notes>
               <Note Audience="All" Ordinal="263" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43538</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="264" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43545</Title>
         <Notes>
               <Note Audience="All" Ordinal="264" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43545</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5013.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="265" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43545</Title>
         <Notes>
               <Note Audience="All" Ordinal="265" Title="Details" Type="Details">This is a vulnerability in  firefox  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43545</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5014.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="266" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24586</Title>
         <Notes>
               <Note Audience="All" Ordinal="266" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn&#39;t require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24586</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="267" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24588</Title>
         <Notes>
               <Note Audience="All" Ordinal="267" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn&#39;t require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24588</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="268" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-42096</Title>
         <Notes>
               <Note Audience="All" Ordinal="268" Title="Details" Type="Details">This is a vulnerability in  mailman:2.1  in Oracle Linux. GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-42096</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4826.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="269" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43538</Title>
         <Notes>
               <Note Audience="All" Ordinal="269" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43538</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="270" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43538</Title>
         <Notes>
               <Note Audience="All" Ordinal="270" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43538</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="271" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43545</Title>
         <Notes>
               <Note Audience="All" Ordinal="271" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43545</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5045.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="272" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-43545</Title>
         <Notes>
               <Note Audience="All" Ordinal="272" Title="Details" Type="Details">This is a vulnerability in  thunderbird  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 4.3 CVSS V3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-43545</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-7</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.3</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-5046.html</URL>
                  <ProductID>P-1309V-7</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="273" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20197</Title>
         <Notes>
               <Note Audience="All" Ordinal="273" Title="Details" Type="Details">This is a vulnerability in  binutils  in Oracle Linux. There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink. CVSS Base Score: 4.2 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20197</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.2</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4364.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="274" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26558</Title>
         <Notes>
               <Note Audience="All" Ordinal="274" Title="Details" Type="Details">This is a vulnerability in  bluez  in Oracle Linux. Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time. CVSS Base Score: 4.2 CVSS V3 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26558</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.2</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4432.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="275" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3635</Title>
         <Notes>
               <Note Audience="All" Ordinal="275" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands. CVSS Base Score: 4.1 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3635</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>4.1</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="276" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-36241</Title>
         <Notes>
               <Note Audience="All" Ordinal="276" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file&#39;s parent is a symlink to a directory outside of the intended extraction location. CVSS Base Score: 3.9 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-36241</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.9</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="277" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-28650</Title>
         <Notes>
               <Note Audience="All" Ordinal="277" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file&#39;s parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241. CVSS Base Score: 3.9 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-28650</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.9</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="278" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20239</Title>
         <Notes>
               <Note Audience="All" Ordinal="278" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality. CVSS Base Score: 3.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20239</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="279" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-15859</Title>
         <Notes>
               <Note Audience="All" Ordinal="279" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data&#39;s address set to the e1000e&#39;s MMIO address. CVSS Base Score: 3.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-15859</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="280" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3592</Title>
         <Notes>
               <Note Audience="All" Ordinal="280" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &#39;bootp_t&#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0. CVSS Base Score: 3.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3592</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="281" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3593</Title>
         <Notes>
               <Note Audience="All" Ordinal="281" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the &#39;udphdr&#39; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0. CVSS Base Score: 3.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3593</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="282" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3594</Title>
         <Notes>
               <Note Audience="All" Ordinal="282" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the &#39;udphdr&#39; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0. CVSS Base Score: 3.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3594</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="283" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3595</Title>
         <Notes>
               <Note Audience="All" Ordinal="283" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the &#39;tftp_t&#39; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0. CVSS Base Score: 3.8 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3595</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.8</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="284" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-22876</Title>
         <Notes>
               <Note Audience="All" Ordinal="284" Title="Details" Type="Details">This is a vulnerability in  curl  in Oracle Linux. curl 7.1.1 to and including 7.75.0 is vulnerable to an &quot;Exposure of Private Personal Information to an Unauthorized Actor&quot; by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. CVSS Base Score: 3.7 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-22876</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.7</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4511.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="285" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20231</Title>
         <Notes>
               <Note Audience="All" Ordinal="285" Title="Details" Type="Details">This is a vulnerability in  gnutls and nettle  in Oracle Linux. A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences. CVSS Base Score: 3.7 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20231</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.7</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4451.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="286" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20232</Title>
         <Notes>
               <Note Audience="All" Ordinal="286" Title="Details" Type="Details">This is a vulnerability in  gnutls and nettle  in Oracle Linux. A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences. CVSS Base Score: 3.7 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20232</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.7</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4451.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="287" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-35603</Title>
         <Notes>
               <Note Audience="All" Ordinal="287" Title="Details" Type="Details">This is a vulnerability in  java-17-openjdk  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 3.7 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-35603</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.7</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4135.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="288" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-14145</Title>
         <Notes>
               <Note Audience="All" Ordinal="288" Title="Details" Type="Details">This is a vulnerability in  openssh  in Oracle Linux. The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected. CVSS Base Score: 3.7 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-14145</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.7</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4368.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="289" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-7068</Title>
         <Notes>
               <Note Audience="All" Ordinal="289" Title="Details" Type="Details">This is a vulnerability in  php:7.4  in Oracle Linux. In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure. CVSS Base Score: 3.6 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-7068</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.6</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4213.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="290" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-26139</Title>
         <Notes>
               <Note Audience="All" Ordinal="290" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients. CVSS Base Score: 3.5 CVSS V3 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-26139</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.5</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="291" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-29623</Title>
         <Notes>
               <Note Audience="All" Ordinal="291" Title="Details" Type="Details">This is a vulnerability in  GNOME  in Oracle Linux. &quot;Clear History and Website Data&quot; did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history. CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-29623</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4381.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="292" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-35448</Title>
         <Notes>
               <Note Audience="All" Ordinal="292" Title="Details" Type="Details">This is a vulnerability in  binutils  in Oracle Linux. An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c. CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-35448</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4364.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="293" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3732</Title>
         <Notes>
               <Note Audience="All" Ordinal="293" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3732</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="294" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-36084</Title>
         <Notes>
               <Note Audience="All" Ordinal="294" Title="Details" Type="Details">This is a vulnerability in  libsepol  in Oracle Linux. The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper). CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-36084</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4513.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="295" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-36085</Title>
         <Notes>
               <Note Audience="All" Ordinal="295" Title="Details" Type="Details">This is a vulnerability in  libsepol  in Oracle Linux. The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map). CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-36085</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4513.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="296" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-36086</Title>
         <Notes>
               <Note Audience="All" Ordinal="296" Title="Details" Type="Details">This is a vulnerability in  libsepol  in Oracle Linux. The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-36086</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4513.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="297" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-36087</Title>
         <Notes>
               <Note Audience="All" Ordinal="297" Title="Details" Type="Details">This is a vulnerability in  libsepol  in Oracle Linux. The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block. CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-36087</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4513.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="298" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3200</Title>
         <Notes>
               <Note Audience="All" Ordinal="298" Title="Details" Type="Details">This is a vulnerability in  libsolv  in Oracle Linux. Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3200</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4408.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="299" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-18442</Title>
         <Notes>
               <Note Audience="All" Ordinal="299" Title="Details" Type="Details">This is a vulnerability in  zziplib  in Oracle Linux. Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value &quot;zzip_file_read&quot; in the function &quot;unzzip_cat_file&quot;. CVSS Base Score: 3.3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-18442</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4316.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="300" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-22898</Title>
         <Notes>
               <Note Audience="All" Ordinal="300" Title="Details" Type="Details">This is a vulnerability in  curl  in Oracle Linux. curl 7.7 through 7.76.1 suffers from an information disclosure when the -t command line option, known as CURLOPT_TELNETOPTIONS in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol. CVSS Base Score: 3.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-22898</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4511.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="301" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-22925</Title>
         <Notes>
               <Note Audience="All" Ordinal="301" Title="Details" Type="Details">This is a vulnerability in  curl  in Oracle Linux. curl supports the -t command line option, known as CURLOPT_TELNETOPTIONSin libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending NEW_ENV variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application. CVSS Base Score: 3.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-22925</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4511.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="302" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2020-24587</Title>
         <Notes>
               <Note Audience="All" Ordinal="302" Title="Details" Type="Details">This is a vulnerability in  kernel  in Oracle Linux. The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn&#39;t require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed. CVSS Base Score: 3.1 CVSS V3 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2020-24587</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.1</BaseScore>
               <Vector>CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4356.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="303" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-20266</Title>
         <Notes>
               <Note Audience="All" Ordinal="303" Title="Details" Type="Details">This is a vulnerability in  rpm  in Oracle Linux. A flaw was found in RPM&#39;s hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability. CVSS Base Score: 3.1 CVSS V3 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-20266</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3.1</BaseScore>
               <Vector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4489.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="304" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-3631</Title>
         <Notes>
               <Note Audience="All" Ordinal="304" Title="Details" Type="Details">This is a vulnerability in  virt:ol and virt-devel:ol  in Oracle Linux. ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. CVSS Base Score: 3 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-3631</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>3</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4191.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
<Vulnerability Ordinal="305" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
        <Title>CVE-2021-27645</Title>
         <Notes>
               <Note Audience="All" Ordinal="305" Title="Details" Type="Details">This is a vulnerability in  glibc  in Oracle Linux. The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c. CVSS Base Score: 2.5 CVSS V3 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L.</Note>
         </Notes>
          <Involvements>
            <Involvement Party="Vendor" Status="Completed">
               <Description>Security patch has been released</Description>
            </Involvement>
          </Involvements>
          <CVE>CVE-2021-27645</CVE>
          <ProductStatuses>
            <Status Type="Known Affected">
               <ProductID>P-1309V-8</ProductID>
            </Status>
          </ProductStatuses>
          <CVSSScoreSets>
           <ScoreSet>
               <BaseScore>2.5</BaseScore>
               <Vector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
           </ScoreSet>
         </CVSSScoreSets>
         <Remediations>
           <Remediation Type="Vendor Resolution">
               <Description>Oracle Linux Security Advisory</Description>
                  <Entitlement xml:lang="en">Oracle Linux customers</Entitlement>
                  <URL>https://linux.oracle.com/errata/ELSA-2021-4358.html</URL>
                  <ProductID>P-1309V-8</ProductID>
            </Remediation>
          </Remediations>
</Vulnerability>
</cvrf:cvrfdoc>
