Oracle Linux Bulletin - October 2016

Description

The Oracle Linux Bulletin lists all CVEs that had been resolved and announced in Oracle Linux Security Advisories (ELSA) in the last one month prior to the release of the bulletin. Oracle Linux Bulletins are published on the same day as Oracle Critical Patch Updates are released. These bulletins will also be updated for the following two months after their release (i.e., the two months between the normal quarterly Critical Patch Update publication dates) to cover all CVEs that had been resolved in those two months following the bulletin's publication. In addition, Oracle Linux Bulletins may also be updated for vulnerability fixes deemed too critical to wait for the next scheduled bulletin publication date.

Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Oracle Linux Bulletin fixes as soon as possible.

Patch Availability

Please see ULN Advisory http://linux.oracle.com/ol-pad-bulletin

Oracle Linux Bulletin Schedule

Oracle Linux Bulletins are released on the Tuesday closest to the 17th day of January, April, July and October. The next four dates are:

  • 17 January 2017
  • 18 April 2017
  • 18 July 2017
  • 17 October 2017

References

Modification History

2016-December-19 Rev 3. New CVEs added.
2016-November-18 Rev 2. New CVEs added.
2016-October-18 Rev 1. Initial Release

Oracle Linux Executive Summary

This Oracle Linux Bulletin contains 181 new security fixes for the Oracle Linux. 96 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.

Oracle Linux Risk Matrix

Revision 3: Published on 2016-12-19

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2016-4794 Oracle Linux Unbreakable Enterprise kernel No 7.2 Local Low None Complete Complete Complete 6,7
CVE-2016-9555 Oracle Linux Unbreakable Enterprise kernel Yes 7.1 Network Medium None None None Complete 6,7
CVE-2016-9555 Oracle Linux Unbreakable Enterprise kernel Yes 7.1 Network Medium None None None Complete 5,6
CVE-2016-1583 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 6,7
CVE-2016-1583 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 5,6
CVE-2016-0718 Oracle Linux expat Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-9079 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-9893 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-9899 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-8704 Oracle Linux memcached Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-8705 Oracle Linux memcached Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-8706 Oracle Linux memcached Yes 6.8 Network Medium None Partial Partial Partial 7
CVE-2016-5290 Oracle Linux thunderbird Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-9079 Oracle Linux thunderbird Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-7032 Oracle Linux sudo No 6.6 Local Medium Single Complete Complete Complete 6,7
CVE-2016-7076 Oracle Linux sudo No 6.6 Local Medium Single Complete Complete Complete 6,7
CVE-2016-8638 Oracle Linux ipsilon Yes 6.4 Network Low None Partial None Partial 7
CVE-2015-8956 Oracle Linux Unbreakable Enterprise kernel No 5.4 Local Medium None Partial None Complete 6,7
CVE-2015-8956 Oracle Linux Unbreakable Enterprise kernel No 5.4 Local Medium None Partial None Complete 5,6
CVE-2016-9897 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-9898 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-9905 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-8650 Oracle Linux Unbreakable Enterprise kernel No 4.9 Local Low None None None Complete 6,7
CVE-2016-3070 Oracle Linux Unbreakable Enterprise kernel No 4.7 Local Medium None None None Complete 6,7
CVE-2016-6480 Oracle Linux Unbreakable Enterprise kernel No 4.7 Local Medium None None None Complete 6,7
CVE-2016-3070 Oracle Linux Unbreakable Enterprise kernel No 4.7 Local Medium None None None Complete 5,6
CVE-2016-6480 Oracle Linux Unbreakable Enterprise kernel No 4.7 Local Medium None None None Complete 5,6
CVE-2016-2053 Oracle Linux Unbreakable Enterprise kernel No 4.6 Local Low Single None None Complete 6,7
CVE-2016-9895 Oracle Linux firefox Yes 4.3 Network Medium None None Partial None 5,6,7
CVE-2016-9900 Oracle Linux firefox Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2016-9901 Oracle Linux firefox Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2016-9902 Oracle Linux firefox Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2016-9904 Oracle Linux firefox Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2016-3699 Oracle Linux Unbreakable Enterprise kernel No 3.3 Local Medium None None Partial Partial 6,7
CVE-2016-6136 Oracle Linux Unbreakable Enterprise kernel No 3.3 Local Medium None Partial None Partial 6,7
CVE-2016-6136 Oracle Linux Unbreakable Enterprise kernel No 3.3 Local Medium None Partial None Partial 5,6
CVE-2016-4569 Oracle Linux Unbreakable Enterprise kernel No 2.1 Local Low None Partial None None 6,7
CVE-2016-4578 Oracle Linux Unbreakable Enterprise kernel No 2.1 Local Low None Partial None None 6,7
CVE-2016-4569 Oracle Linux Unbreakable Enterprise kernel No 2.1 Local Low None Partial None None 5,6
CVE-2016-4578 Oracle Linux Unbreakable Enterprise kernel No 2.1 Local Low None Partial None None 5,6

Revision 2: Published on 2016-11-18

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2016-4794 Oracle Linux kernel No 7.2 Local Low None Complete Complete Complete 7
CVE-2016-6662 Oracle Linux mariadb No 7.1 Network High Single Complete Complete Complete 7
CVE-2016-1583 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 6,7
CVE-2016-5195 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 6,7
CVE-2016-1583 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 5,6
CVE-2016-5195 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 5
CVE-2016-5195 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 6,7
CVE-2015-8812 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 7
CVE-2016-3841 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 7
CVE-2016-5829 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 7
CVE-2016-5195 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 5,6
CVE-2016-5290 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-5296 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-5582 Oracle Linux java-1.7.0-openjdk Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-5582 Oracle Linux java-1.8.0-openjdk Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-7545 Oracle Linux policycoreutils Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2016-7050 Oracle Linux resteasy-base Yes 6.8 Network Medium None Partial Partial Partial 7
CVE-2016-0714 Oracle Linux tomcat Yes 6.8 Network Medium None Partial Partial Partial 7
CVE-2016-4971 Oracle Linux wget Yes 6.8 Network Medium None Partial Partial Partial 7
CVE-2016-5423 Oracle Linux postgresql No 6.5 Network Low Single Partial Partial Partial 7
CVE-2016-2143 Oracle Linux kernel No 6.2 Local High None Complete Complete Complete 6
CVE-2016-2384 Oracle Linux kernel No 6.2 Local High None Complete Complete Complete 7
CVE-2015-8325 Oracle Linux openssh No 6.2 Local High None Complete Complete Complete 7
CVE-2016-5424 Oracle Linux postgresql No 6.0 Network Medium Single Partial Partial Partial 7
CVE-2016-5419 Oracle Linux curl Yes 5.8 Network Medium None Partial Partial None 7
CVE-2015-8803 Oracle Linux nettle Yes 5.8 Network Medium None Partial Partial None 7
CVE-2015-8804 Oracle Linux nettle Yes 5.8 Network Medium None Partial Partial None 7
CVE-2015-8805 Oracle Linux nettle Yes 5.8 Network Medium None Partial Partial None 7
CVE-2016-6489 Oracle Linux nettle Yes 5.8 Network Medium None Partial Partial None 7
CVE-2015-7979 Oracle Linux ntp Yes 5.8 Network Medium None None Partial Partial 7
CVE-2016-7795 Oracle Linux systemd No 5.6 Local Low None None Partial Complete 7
CVE-2015-8956 Oracle Linux kernel No 5.4 Local Medium None Partial None Complete 7
CVE-2016-5297 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-9066 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5573 Oracle Linux java-1.7.0-openjdk Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5573 Oracle Linux java-1.8.0-openjdk Yes 5.1 Network High None Partial Partial Partial 6,7
CVE-2016-5008 Oracle Linux libvirt Yes 5.1 Network High None Partial Partial Partial 7
CVE-2016-2834 Oracle Linux nss and nss-util Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5399 Oracle Linux php Yes 5.1 Network High None Partial Partial Partial 7
CVE-2016-5766 Oracle Linux php Yes 5.1 Network High None Partial Partial Partial 7
CVE-2016-5767 Oracle Linux php Yes 5.1 Network High None Partial Partial Partial 7
CVE-2015-8868 Oracle Linux poppler Yes 5.1 Network High None Partial Partial Partial 7
CVE-2016-5416 Oracle Linux 389-ds-base Yes 5.0 Network Low None Partial None None 6,7
CVE-2016-2848 Oracle Linux bind Yes 5.0 Network Low None None None Partial 5,6
CVE-2016-8864 Oracle Linux bind Yes 5.0 Network Low None None None Partial 5,6,7
CVE-2016-2848 Oracle Linux bind97 Yes 5.0 Network Low None None None Partial 5
CVE-2016-8864 Oracle Linux bind97 Yes 5.0 Network Low None None None Partial 5
CVE-2016-5361 Oracle Linux libreswan Yes 5.0 Network Low None None None Partial 7
CVE-2016-2569 Oracle Linux squid Yes 5.0 Network Low None None None Partial 7
CVE-2016-2570 Oracle Linux squid Yes 5.0 Network Low None None None Partial 7
CVE-2016-2571 Oracle Linux squid Yes 5.0 Network Low None None None Partial 7
CVE-2016-2572 Oracle Linux squid Yes 5.0 Network Low None None None Partial 7
CVE-2016-3948 Oracle Linux squid Yes 5.0 Network Low None None None Partial 7
CVE-2015-5345 Oracle Linux tomcat Yes 5.0 Network Low None Partial None None 7
CVE-2016-5420 Oracle Linux curl No 4.9 Network Medium Single Partial Partial None 7
CVE-2016-7141 Oracle Linux curl No 4.9 Network Medium Single Partial Partial None 7
CVE-2013-4312 Oracle Linux kernel No 4.9 Local Low None None None Complete 7
CVE-2016-2847 Oracle Linux kernel No 4.9 Local Low None None None Complete 7
CVE-2015-5313 Oracle Linux libvirt No 4.9 Network High Single None Complete None 7
CVE-2016-5011 Oracle Linux util-linux No 4.9 Local Low None None None Complete 7
CVE-2016-3070 Oracle Linux kernel No 4.7 Local Medium None None None Complete 7
CVE-2016-4581 Oracle Linux kernel No 4.7 Local Medium None None None Complete 7
CVE-2016-6198 Oracle Linux kernel No 4.7 Local Medium None None None Complete 7
CVE-2016-6327 Oracle Linux kernel No 4.7 Local Medium None None None Complete 7
CVE-2016-6480 Oracle Linux kernel No 4.7 Local Medium None None None Complete 7
CVE-2015-8543 Oracle Linux kernel No 4.6 Local Low Single None None Complete 7
CVE-2016-2053 Oracle Linux kernel No 4.6 Local Low Single None None Complete 7
CVE-2016-5410 Oracle Linux firewalld No 4.4 Local Medium None Partial Partial Partial 7
CVE-2015-8844 Oracle Linux kernel No 4.4 Local Medium Single None None Complete 7
CVE-2015-8845 Oracle Linux kernel No 4.4 Local Medium Single None None Complete 7
CVE-2015-8869 Oracle Linux libguestfs and virt-p2v No 4.4 Local Medium None Partial Partial Partial 7
CVE-2016-5636 Oracle Linux python No 4.4 Local Medium None Partial Partial Partial 7
CVE-2015-5351 Oracle Linux tomcat No 4.4 Local Medium None Partial Partial Partial 7
CVE-2016-5291 Oracle Linux firefox Yes 4.3 Network Medium None None Partial None 5,6,7
CVE-2016-9064 Oracle Linux firefox Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2016-5554 Oracle Linux java-1.7.0-openjdk Yes 4.3 Network Medium None None Partial None 5,6,7
CVE-2016-5554 Oracle Linux java-1.8.0-openjdk Yes 4.3 Network Medium None None Partial None 6,7
CVE-2016-5412 Oracle Linux kernel No 4.3 Adjacent network High Single None None Complete 7
CVE-2016-5285 Oracle Linux nss and nss-util Yes 4.3 Network Medium None None None Partial 5,6,7
CVE-2016-8635 Oracle Linux nss and nss-util Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2015-7701 Oracle Linux ntp Yes 4.3 Network Medium None None None Partial 7
CVE-2015-7852 Oracle Linux ntp Yes 4.3 Network Medium None None None Partial 7
CVE-2015-7977 Oracle Linux ntp Yes 4.3 Network Medium None None None Partial 7
CVE-2015-7978 Oracle Linux ntp Yes 4.3 Network Medium None None None Partial 7
CVE-2015-8158 Oracle Linux ntp Yes 4.3 Network Medium None None None Partial 7
CVE-2016-0763 Oracle Linux tomcat No 4.3 Adjacent network Medium None Partial Partial None 7
CVE-2016-3092 Oracle Linux tomcat Yes 4.3 Network Medium None None None Partial 7
CVE-2016-5828 Oracle Linux kernel No 4.0 Local High None None None Complete 7
CVE-2016-6313 Oracle Linux libgcrypt Yes 4.0 Network High None Partial Partial None 6,7
CVE-2016-3492 Oracle Linux mariadb No 4.0 Network Low Single None None Partial 7
CVE-2016-5612 Oracle Linux mariadb No 4.0 Network Low Single None None Partial 7
CVE-2016-5624 Oracle Linux mariadb No 4.0 Network Low Single None None Partial 7
CVE-2016-5626 Oracle Linux mariadb No 4.0 Network Low Single None None Partial 7
CVE-2016-5629 Oracle Linux mariadb No 4.0 Network Low Single None None Partial 7
CVE-2016-8283 Oracle Linux mariadb No 4.0 Network Low Single None None Partial 7
CVE-2015-5194 Oracle Linux ntp No 4.0 Network Low Single None Partial None 7
CVE-2015-5195 Oracle Linux ntp No 4.0 Network Low Single None Partial None 7
CVE-2015-5196 Oracle Linux ntp No 4.0 Network Low Single None Partial None 7
CVE-2015-7691 Oracle Linux ntp Yes 4.0 Network High None Partial None Partial 7
CVE-2015-7692 Oracle Linux ntp Yes 4.0 Network High None Partial None Partial 7
CVE-2015-7702 Oracle Linux ntp Yes 4.0 Network High None Partial None Partial 7
CVE-2015-7703 Oracle Linux ntp No 4.0 Network Low Single None Partial None 7
CVE-2015-5174 Oracle Linux tomcat No 4.0 Network Low Single Partial None None 7
CVE-2015-8746 Oracle Linux kernel No 3.8 Local High Single None None Complete 7
CVE-2016-3712 Oracle Linux qemu-kvm No 3.8 Adjacent network Medium Single Partial None Partial 7
CVE-2016-5384 Oracle Linux fontconfig No 3.7 Local High None Partial Partial Partial 7
CVE-2016-3075 Oracle Linux glibc No 3.7 Local High None Partial Partial Partial 7
CVE-2016-2069 Oracle Linux kernel No 3.7 Local High None Partial Partial Partial 7
CVE-2015-7974 Oracle Linux ntp No 3.6 Network High Single None Partial Partial 7
CVE-2016-7091 Oracle Linux sudo No 3.6 Local Low None Partial Partial None 7
CVE-2016-4992 Oracle Linux 389-ds-base No 3.5 Network Medium Single Partial None None 6,7
CVE-2015-8374 Oracle Linux kernel No 3.5 Network Medium Single Partial None None 7
CVE-2016-3120 Oracle Linux krb5 No 3.5 Network Medium Single None None Partial 7
CVE-2016-5616 Oracle Linux mariadb No 3.5 Local High Single Partial Partial Partial 7
CVE-2016-6663 Oracle Linux mariadb No 3.5 Local High Single Partial Partial Partial 7
CVE-2016-3699 Oracle Linux kernel No 3.3 Local Medium None None Partial Partial 7
CVE-2016-6136 Oracle Linux kernel No 3.3 Local Medium None Partial None Partial 7
CVE-2015-5219 Oracle Linux ntp No 3.3 Adjacent network Low None None None Partial 7
CVE-2016-0706 Oracle Linux tomcat No 2.9 Adjacent network Medium None Partial None None 7
CVE-2016-5405 Oracle Linux 389-ds-base Yes 2.6 Network High None Partial None None 6,7
CVE-2016-2774 Oracle Linux dhcp Yes 2.6 Network High None None None Partial 7
CVE-2016-4994 Oracle Linux gimp Yes 2.6 Network High None None None Partial 7
CVE-2016-5542 Oracle Linux java-1.7.0-openjdk Yes 2.6 Network High None None Partial None 5,6,7
CVE-2016-5597 Oracle Linux java-1.7.0-openjdk Yes 2.6 Network High None Partial None None 5,6,7
CVE-2016-5542 Oracle Linux java-1.8.0-openjdk Yes 2.6 Network High None None Partial None 6,7
CVE-2016-5597 Oracle Linux java-1.8.0-openjdk Yes 2.6 Network High None Partial None None 6,7
CVE-2016-2117 Oracle Linux kernel Yes 2.6 Network High None Partial None None 7
CVE-2016-5768 Oracle Linux php Yes 2.6 Network High None None None Partial 7
CVE-2016-1981 Oracle Linux qemu-kvm No 2.3 Adjacent network Medium Single None None Partial 7
CVE-2016-0764 Oracle Linux NetworkManager No 2.1 Local Low None Partial None None 7
CVE-2016-4569 Oracle Linux kernel No 2.1 Local Low None Partial None None 7
CVE-2016-4578 Oracle Linux kernel No 2.1 Local Low None Partial None None 7
CVE-2016-3119 Oracle Linux krb5 No 2.1 Network High Single None None Partial 7
CVE-2015-5160 Oracle Linux libvirt No 2.1 Local Low None Partial None None 7
CVE-2016-3099 Oracle Linux mod_nss No 1.9 Local Medium None None Partial None 7
CVE-2016-3156 Oracle Linux kernel No 1.7 Local Low Single None None Partial 7

Revision 1: Published on 2016-10-18

CVE# Product Component Remote Exploit without Auth.? CVSS VERSION 2.0 RISK (see Risk Matrix Definitions) Supported Versions Affected
Base Score Access Vector Access Complexity Authen­tication Confid­entiality Inte­grity Avail­ability
CVE-2016-4997 Oracle Linux Unbreakable Enterprise kernel No 7.2 Local Low None Complete Complete Complete 6,7
CVE-2016-4997 Oracle Linux Unbreakable Enterprise kernel No 7.2 Local Low None Complete Complete Complete 5,6
CVE-2016-7039 Oracle Linux Unbreakable Enterprise kernel Yes 7.1 Network Medium None None None Complete 6,7
CVE-2016-7039 Oracle Linux kernel Yes 7.1 Network Medium None None None Complete 7
CVE-2016-5829 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 6,7
CVE-2016-4470 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 6
CVE-2016-5829 Oracle Linux kernel No 6.9 Local Medium None Complete Complete Complete 6
CVE-2016-5425 Oracle Linux tomcat No 6.9 Local Medium None Complete Complete Complete 7
CVE-2016-6325 Oracle Linux tomcat No 6.9 Local Medium None Complete Complete Complete 7
CVE-2016-6325 Oracle Linux tomcat6 No 6.9 Local Medium None Complete Complete Complete 6
CVE-2016-5829 Oracle Linux Unbreakable Enterprise kernel No 6.9 Local Medium None Complete Complete Complete 5,6
CVE-2016-5257 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-5278 Oracle Linux firefox Yes 6.8 Network Medium None Partial Partial Partial 5,6,7
CVE-2016-5257 Oracle Linux thunderbird Yes 6.8 Network Medium None Partial Partial Partial 6,7
CVE-2015-5346 Oracle Linux tomcat Yes 6.8 Network Medium None Partial Partial Partial 7
CVE-2016-0714 Oracle Linux tomcat6 Yes 6.8 Network Medium None Partial Partial Partial 6
CVE-2016-3710 Oracle Linux kvm No 6.5 Adjacent network High Single Complete Complete Complete 5
CVE-2016-3134 Oracle Linux Unbreakable Enterprise kernel No 6.2 Local High None Complete Complete Complete 6,7
CVE-2016-3134 Oracle Linux Unbreakable Enterprise kernel No 6.2 Local High None Complete Complete Complete 5,6
CVE-2014-7810 Oracle Linux tomcat Yes 5.8 Network Medium None Partial Partial None 7
CVE-2016-4998 Oracle Linux Unbreakable Enterprise kernel No 5.6 Local Low None Partial None Complete 6,7
CVE-2016-4998 Oracle Linux Unbreakable Enterprise kernel No 5.6 Local Low None Partial None Complete 5,6
CVE-2016-5261 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5270 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5272 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5274 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5276 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5277 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5280 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5281 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-5284 Oracle Linux firefox Yes 5.1 Network High None Partial Partial Partial 5,6,7
CVE-2016-2776 Oracle Linux bind Yes 5.0 Network Low None None None Partial 5,6,7
CVE-2016-2776 Oracle Linux bind97 Yes 5.0 Network Low None None None Partial 5
CVE-2016-2179 Oracle Linux openssl Yes 5.0 Network Low None None None Partial 6,7
CVE-2016-6304 Oracle Linux openssl Yes 5.0 Network Low None None None Partial 6,7
CVE-2016-1000111 Oracle Linux python-twisted-web Yes 5.0 Network Undefined None None None None 6
CVE-2015-5345 Oracle Linux tomcat6 Yes 5.0 Network Low None Partial None None 6
CVE-2016-5250 Oracle Linux firefox Yes 4.3 Network Medium None Partial None None 5,6,7
CVE-2016-2181 Oracle Linux openssl Yes 4.3 Network Medium None None None Partial 6,7
CVE-2016-2182 Oracle Linux openssl Yes 4.3 Network Medium None None None Partial 5,6,7
CVE-2016-2183 Oracle Linux openssl Yes 4.3 Network Medium None Partial None None 5
CVE-2016-6302 Oracle Linux openssl Yes 4.3 Network Medium None None None Partial 6,7
CVE-2015-5174 Oracle Linux tomcat6 No 4.0 Network Low Single Partial None None 6
CVE-2015-8374 Oracle Linux Unbreakable Enterprise kernel No 3.5 Network Medium Single Partial None None 5,6
CVE-2016-0706 Oracle Linux tomcat6 No 2.9 Adjacent network Medium None Partial None None 6
CVE-2016-2177 Oracle Linux openssl Yes 2.6 Network High None None None Partial 5,6,7
CVE-2016-5388 Oracle Linux tomcat Yes 2.6 Network High None None Partial None 7
CVE-2016-5388 Oracle Linux tomcat6 Yes 2.6 Network High None None Partial None 6
CVE-2016-5403 Oracle Linux kvm No 2.3 Adjacent network Medium Single None None Partial 5
CVE-2016-2178 Oracle Linux openssl No 1.9 Local Medium None Partial None None 5,6,7
CVE-2016-2180 Oracle Linux openssl No 1.9 Local Medium None None None Partial 6,7
CVE-2016-6306 Oracle Linux openssl No 1.2 Local High None None None Partial 5,6,7