cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 11 of 28
CVE-2014-9666P4MEDIUMCVSS 6.8v10.0v11.22015-02-08
CVE-2014-9666 [MEDIUM] CWE-189 CVE-2014-9666: The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.
nvd
CVE-2010-2382P4LOWCVSS 3.2PoCv8v9+1 more2010-07-13
CVE-2010-2382 [LOW] CVE-2010-2382: Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentialit Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2010-2384P4LOWCVSS 3.2PoCv9v102010-07-13
CVE-2010-2384 [LOW] CVE-2010-2384: Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality an Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console.
nvd
CVE-2026-21928P4MEDIUMCVSS 5.3v112026-01-20
CVE-2026-21928 [MEDIUM] CWE-200 CVE-2026-21928: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle
nvd
CVE-2015-0248P4MEDIUMCVSS 5.0v11.32015-04-08
CVE-2015-0248 [MEDIUM] CWE-399 CVE-2015-0248: The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1. The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers.
nvd
CVE-2016-0546P4HIGHCVSS 7.2v11.32016-01-21
CVE-2016-0546 [HIGH] CVE-2016-0546: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commen
nvd
CVE-2014-1502P4MEDIUMCVSS 6.8v11.32014-03-19
CVE-2014-1502 [MEDIUM] CWE-346 CVE-2014-1502: The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefo The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.
nvd
CVE-2014-2440P4MEDIUMCVSS 5.1v11.32014-04-16
CVE-2014-2440 [MEDIUM] CVE-2014-2440: Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2015-2774P4MEDIUMCVSS 5.9v11.22016-04-07
CVE-2015-2774 [MEDIUM] CVE-2015-2774: Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, w Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
nvd
CVE-2020-2558P4MEDIUMCVSS 5.8v112020-01-15
CVE-2020-2558 [MEDIUM] CVE-2020-2558: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successfu
nvd
CVE-2018-3267P4MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3267 [MEDIUM] CVE-2018-3267: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LFTP). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via FTP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Sola
nvd
CVE-2014-2497P4MEDIUMCVSS 4.3v11.22014-03-21
CVE-2014-2497 [MEDIUM] CWE-476 CVE-2014-2497: The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows rem The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
nvd
CVE-2019-2543P4MEDIUMCVSS 5.3v10v112019-01-16
CVE-2019-2543 [MEDIUM] CVE-2019-2543: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Ke Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via KSSL to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2015-3294P4MEDIUMCVSS 6.4v11.22015-05-08
CVE-2015-3294 [MEDIUM] CWE-19 CVE-2015-3294: The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.
nvd
CVE-2015-8786P4MEDIUMCVSS 6.5v11.32016-12-09
CVE-2015-8786 [MEDIUM] CWE-399 CVE-2015-8786: The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privil The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
nvd
CVE-2010-2383P4LOWCVSS 3.2PoCv8v9+1 more2010-07-13
CVE-2010-2383 [LOW] CVE-2010-2383: Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to aff Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS.
nvd
CVE-2015-1819P4MEDIUMCVSS 5.0v11.32015-08-14
CVE-2015-1819 [MEDIUM] CWE-399 CVE-2015-1819: The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) vi The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
nvd
CVE-2015-8629P4MEDIUMCVSS 5.3v10v11.32016-02-13
CVE-2015-8629 [MEDIUM] CWE-125 CVE-2015-8629: The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) befo The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.
nvd
CVE-2011-4093P4MEDIUMCVSS 5.8v11.22014-02-10
CVE-2011-4093 [MEDIUM] CWE-190 CVE-2011-4093: Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.
nvd
CVE-2020-2578P4MEDIUMCVSS 5.8v112020-01-15
CVE-2020-2578 [MEDIUM] CVE-2020-2578: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successfu
nvd
Oracle Solaris vulnerabilities | cvebase