cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 10 of 28
CVE-2015-2739P4CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2739 [CRITICAL] CWE-119 CVE-2015-2739: The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2015-2737P4CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2737 [CRITICAL] CWE-17 CVE-2015-2737: The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39 The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2023-21985P4HIGHCVSS 7.7v10v112023-04-18
CVE-2023-21985 [HIGH] CWE-284 CVE-2023-21985: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versi Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person o
nvd
CVE-2014-6530P4MEDIUMCVSS 6.5v11.32014-10-15
CVE-2014-6530 [MEDIUM] CVE-2014-6530: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to CLIENT:MYSQLDUMP.
nvd
CVE-2018-1171P4HIGHCVSS 7.0v10v11.32018-03-19
CVE-2018-1171 [HIGH] CWE-787 CVE-2018-1171: This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joye This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the DTrace DOF files. The issue results fro
nvd
CVE-2013-6629P4MEDIUMCVSS 5.0v11.32013-11-19
CVE-2013-6629 [MEDIUM] CWE-200 CVE-2013-6629: The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive
nvd
CVE-2015-4487P4HIGHCVSS 7.5v11.32015-08-16
CVE-2015-4487 [HIGH] CWE-119 CVE-2015-4487: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
nvd
CVE-2013-5619P4HIGHCVSS 7.5v11.32013-12-11
CVE-2013-5619 [HIGH] CWE-190 CVE-2013-5619: Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox be Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2019-13057P4MEDIUMCVSS 4.9v112019-07-26
CVE-2019-13057 [MEDIUM] CVE-2019-13057: An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator deleg An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or
nvd
CVE-2014-6469P4MEDIUMCVSS 6.8v11.32014-10-15
CVE-2014-6469 [MEDIUM] CVE-2014-6469: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER.
nvd
CVE-2015-0253P4MEDIUMCVSS 5.0v11.32015-07-20
CVE-2015-0253 [MEDIUM] CVE-2015-0253: The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initia The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400
nvd
CVE-2019-16168P4MEDIUMCVSS 6.5v112019-09-09
CVE-2019-16168 [MEDIUM] CWE-369 CVE-2019-16168: In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other applicati In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
nvd
CVE-2014-4258P4MEDIUMCVSS 6.5v11.32014-07-17
CVE-2014-4258 [MEDIUM] CVE-2014-4258: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.
nvd
CVE-2014-8964P4MEDIUMCVSS 5.0v11.22014-12-16
CVE-2014-8964 [MEDIUM] CWE-119 CVE-2014-8964: Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of ser Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
nvd
CVE-2025-30690P4HIGHCVSS 7.2v112025-04-15
CVE-2025-30690 [HIGH] CWE-284 CVE-2025-30690: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The support Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person oth
nvd
CVE-2023-21896P4HIGHCVSS 7.0v10v112023-04-18
CVE-2023-21896 [HIGH] CWE-269 CVE-2023-21896: Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported vers Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in tak
nvd
CVE-2015-4489P4HIGHCVSS 7.5v11.32015-08-16
CVE-2015-4489 [HIGH] CWE-119 CVE-2015-4489: The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
nvd
CVE-2018-3263P4MEDIUMCVSS 5.6v11.32018-10-17
CVE-2018-3263 [MEDIUM] CVE-2018-3263: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Sudo). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2011-3537P4HIGHCVSS 7.8v8v9+2 more2011-10-18
CVE-2011-3537 [HIGH] CVE-2011-3537: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect av Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Filesystem.
nvd
CVE-2014-9664P4MEDIUMCVSS 6.8v10.0v11.22015-02-08
CVE-2014-9664 [MEDIUM] CWE-119 CVE-2014-9664: FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which a FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
nvd
Oracle Solaris vulnerabilities | cvebase