cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 13 of 28
CVE-2016-3584P4HIGHCVSS 7.0v11.32016-07-21
CVE-2016-3584 [HIGH] CVE-2016-3584: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality, i Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality, integrity, and availability via vectors related to Libadimalloc.
nvd
CVE-2015-5963P4MEDIUMCVSS 5.0v11.32015-08-24
CVE-2015-5963 [MEDIUM] CWE-399 CVE-2015-5963: contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4 contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record removal) via a large number of requests to contrib.auth.views.logout, which triggers the creation of an empty
nvd
CVE-2015-2316P4MEDIUMCVSS 5.0v11.22015-03-25
CVE-2015-2316 [MEDIUM] CWE-399 CVE-2015-2316: The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x befo The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.
nvd
CVE-2017-10004P4MEDIUMCVSS 6.7v10v112017-08-08
CVE-2017-10004 [MEDIUM] CVE-2017-10004: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover
nvd
CVE-2016-4079P4MEDIUMCVSS 5.9v11.32016-04-25
CVE-2016-4079 [MEDIUM] CWE-119 CVE-2016-4079: epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x bef epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.
nvd
CVE-2018-3274P4MEDIUMCVSS 5.7v11.32018-10-17
CVE-2018-3274 [MEDIUM] CVE-2018-3274: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Solaris. Successful attacks require human interaction from a person other than the attacker. Successful atta
nvd
CVE-2015-4879P4MEDIUMCVSS 4.6v11.32015-10-21
CVE-2015-4879 [MEDIUM] CVE-2015-4879: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
nvd
CVE-2015-4020P4MEDIUMCVSS 4.3v11.32015-08-25
CVE-2015-4020 [MEDIUM] CVE-2015-4020: RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostn RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a "DNS hijack attack." NOTE: this vulnerability
nvd
CVE-2015-1270P4MEDIUMCVSS 6.8v11.32015-07-23
CVE-2015-1270 [MEDIUM] CWE-19 CVE-2015-1270: The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted f
nvd
CVE-2014-9672P4MEDIUMCVSS 5.8v10.0v11.22015-02-08
CVE-2014-9672 [MEDIUM] CWE-119 CVE-2014-9672: Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
nvd
CVE-2015-2577P4HIGHCVSS 7.2v102015-04-16
CVE-2015-2577 [HIGH] CVE-2015-2577: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, int Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Accounting commands.
nvd
CVE-2015-0251P4MEDIUMCVSS 4.0v11.32015-04-08
CVE-2015-0251 [MEDIUM] CWE-345 CVE-2015-0251: The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote aut The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
nvd
CVE-2015-5964P4MEDIUMCVSS 5.0v11.32015-08-24
CVE-2015-5964 [MEDIUM] CWE-399 CVE-2015-5964: The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functio The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote attackers to cause a denial of service (session store consumption) via unspecified vectors.
nvd
CVE-2014-4260P4MEDIUMCVSS 5.5v11.32014-07-17
CVE-2014-4260 [MEDIUM] CVE-2014-4260: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
nvd
CVE-2015-2188P4MEDIUMCVSS 5.0v11.22015-03-08
CVE-2015-2188 [MEDIUM] CWE-19 CVE-2015-2188: epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x befo epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that is improperly handled during decompression.
nvd
CVE-2017-3551P4MEDIUMCVSS 6.6v11.32017-04-24
CVE-2017-3551 [MEDIUM] CVE-2017-3551: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Libraries). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in
nvd
CVE-2015-5295P4MEDIUMCVSS 5.4v11.32016-01-20
CVE-2015-5295 [MEDIUM] CWE-119 CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
nvd
CVE-2025-53068P4MEDIUMCVSS 6.5v112025-10-21
CVE-2025-53068 [MEDIUM] CWE-400 CVE-2025-53068: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significa
nvd
CVE-2026-34281P4MEDIUMCVSS 6.5v11.42026-04-21
CVE-2026-34281 [MEDIUM] CWE-400 CVE-2026-34281: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may signifi
nvd
CVE-2015-0381P4MEDIUMCVSS 4.3v11.32015-01-21
CVE-2015-0381 [MEDIUM] CVE-2015-0381: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.
nvd
Oracle Solaris vulnerabilities | cvebase