cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 14 of 28
CVE-2015-2620P4MEDIUMCVSS 4.3v11.32015-07-16
CVE-2015-2620 [MEDIUM] CVE-2015-2620: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2015-3814P4MEDIUMCVSS 5.0v11.22015-05-26
CVE-2015-3814 [MEDIUM] CWE-189 CVE-2015-3814: The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee802 The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error condition, which allows remote attackers to cause a denial of service (infinite loop) via a crafted pac
nvd
CVE-2014-6559P4MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6559 [MEDIUM] CVE-2014-6559: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
nvd
CVE-2016-5844P4MEDIUMCVSS 6.5v11.32016-09-21
CVE-2016-5844 [MEDIUM] CWE-190 CVE-2016-5844: Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a den Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
nvd
CVE-2015-4819P4HIGHCVSS 7.2v11.32015-10-21
CVE-2015-4819 [HIGH] CVE-2015-4819: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client programs.
nvd
CVE-2015-0561P4MEDIUMCVSS 5.0v11.22015-01-10
CVE-2015-0561 [MEDIUM] CWE-20 CVE-2015-0561: asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 do asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet.
nvd
CVE-2015-2189P4MEDIUMCVSS 5.0v11.22015-03-08
CVE-2015-2189 [MEDIUM] CWE-189 CVE-2015-2189: Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wiresh Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet.
nvd
CVE-2014-1561P4MEDIUMCVSS 5.8v11.32014-07-23
CVE-2014-1561 [MEDIUM] CWE-264 CVE-2014-1561: Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customiz Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.
nvd
CVE-2019-2788P4MEDIUMCVSS 6.3v11.42019-07-23
CVE-2019-2788 [MEDIUM] CVE-2019-2788: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Open Fabr Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Open Fabrics Tools). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a per
nvd
CVE-2015-2190P4MEDIUMCVSS 5.0v11.22015-03-08
CVE-2015-2190 [MEDIUM] CWE-19 CVE-2015-2190: epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater t epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet that is improperly handled by the LLDP dissector.
nvd
CVE-2014-6494P4MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6494 [MEDIUM] CVE-2014-6494: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.
nvd
CVE-2021-2192P4MEDIUMCVSS 6.1v112021-04-22
CVE-2021-2192 [MEDIUM] CVE-2021-2192: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2018-2753P4MEDIUMCVSS 6.0v11.32018-04-19
CVE-2018-2753 [MEDIUM] CVE-2018-2753: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Python mo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Python modules). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person o
nvd
CVE-2011-4091P4MEDIUMCVSS 5.0v11.22014-02-10
CVE-2011-4091 [MEDIUM] CWE-287 CVE-2011-4091: The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentica The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.
nvd
CVE-2015-5144P4MEDIUMCVSS 4.3v11.32015-07-14
CVE-2015-5144 [MEDIUM] CWE-20 CVE-2015-5144: Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorr Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to
nvd
CVE-2022-21461P4MEDIUMCVSS 5.5v112022-04-19
CVE-2022-21461 [MEDIUM] CVE-2022-21461: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized acces
nvd
CVE-2015-2631P4HIGHCVSS 7.2v10v11.22015-07-16
CVE-2015-2631 [HIGH] CVE-2015-2631: Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentia Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rmformat.
nvd
CVE-2016-0414P4HIGHCVSS 7.2v112016-01-21
CVE-2016-0414 [HIGH] CVE-2016-0414: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, int Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0418.
nvd
CVE-2014-1506P4MEDIUMCVSS 6.4v11.32014-03-19
CVE-2014-1506 [MEDIUM] CWE-22 CVE-2014-1506: Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Androi Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.
nvd
CVE-2016-5357P4MEDIUMCVSS 5.9v11.32016-08-07
CVE-2016-5357 [MEDIUM] CWE-20 CVE-2016-5357: wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2 wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
nvd
Oracle Solaris vulnerabilities | cvebase