cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 12 of 28
CVE-2014-1501P4MEDIUMCVSS 5.8v11.32014-03-19
CVE-2014-1501 [MEDIUM] CWE-264 CVE-2014-1501: Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
nvd
CVE-2016-5566P4MEDIUMCVSS 5.3v11.32016-10-25
CVE-2016-5566 [MEDIUM] CWE-284 CVE-2016-5566: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect confidentiali Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2014-9669P4MEDIUMCVSS 6.8v10.0v11.22015-02-08
CVE-2014-9669 [MEDIUM] CWE-125 CVE-2014-9669: Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2015-0382P4MEDIUMCVSS 4.3v11.32015-01-21
CVE-2015-0382 [MEDIUM] CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
nvd
CVE-2019-2704P4MEDIUMCVSS 5.3v112019-04-23
CVE-2019-2704 [MEDIUM] CVE-2019-2704: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: IP Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: IPS Package Manager). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized rea
nvd
CVE-2013-4590P4MEDIUMCVSS 4.3v11.22014-02-26
CVE-2013-4590 [MEDIUM] CWE-200 CVE-2013-4590: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to a
nvd
CVE-2015-2695P4MEDIUMCVSS 5.0v11.32015-11-09
CVE-2015-2695 [MEDIUM] CWE-763 CVE-2015-2695: lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
nvd
CVE-2018-2578P4HIGHCVSS 7.2v11.32018-01-18
CVE-2018-2578 [HIGH] CVE-2018-2578: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than
nvd
CVE-2016-4085P4MEDIUMCVSS 5.9v11.32016-04-25
CVE-2016-4085 [MEDIUM] CWE-20 CVE-2016-4085: Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a packet.
nvd
CVE-2019-12387P4MEDIUMCVSS 6.1v112019-06-10
CVE-2019-12387 [MEDIUM] CWE-74 CVE-2019-12387: In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v10v112019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2018-2717P4MEDIUMCVSS 6.6v10.0v11.32018-01-18
CVE-2018-2717 [MEDIUM] CVE-2018-2717: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SPARC Pla Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SPARC Platform). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a pers
nvd
CVE-2022-21271P4MEDIUMCVSS 5.3v112022-01-19
CVE-2022-21271 [MEDIUM] CVE-2022-21271: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoc
nvd
CVE-2018-3172P4MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3172 [MEDIUM] CVE-2018-3172: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Sup Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Supported versions that are affected are 10 and 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via Portmap v3 to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2018-3268P4MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3268 [MEDIUM] CVE-2018-3268: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Serve Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partia
nvd
CVE-2015-0798P4MEDIUMCVSS 5.0v11.32015-04-08
CVE-2015-0798 [MEDIUM] CWE-264 CVE-2015-0798: The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.
nvd
CVE-2026-21927P4MEDIUMCVSS 5.8v10v112026-01-20
CVE-2026-21927 [MEDIUM] CVE-2026-21927: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the
nvd
CVE-2026-21935P4MEDIUMCVSS 5.8v112026-01-20
CVE-2026-21935 [MEDIUM] CVE-2026-21935: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the
nvd
CVE-2020-2605P4HIGHCVSS 7.1v112020-01-15
CVE-2020-2605 [HIGH] CVE-2020-2605: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized creat
nvd
CVE-2014-6507P4MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6507 [MEDIUM] CVE-2014-6507: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.
nvd