Oracle Solaris vulnerabilities
551 known vulnerabilities affecting oracle/solaris.
Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103
Vulnerabilities
Page 15 of 28
CVE-2016-4082P4MEDIUMCVSS 5.9v11.32016-04-25
CVE-2016-4082 [MEDIUM] CWE-119 CVE-2016-4082: epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2
epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.
nvd
CVE-2014-9601P4MEDIUMCVSS 5.0v11.22015-01-16
CVE-2014-9601 [MEDIUM] CWE-20 CVE-2014-9601: Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
nvd
CVE-2021-35539P4MEDIUMCVSS 6.5v112021-10-20
CVE-2021-35539 [MEDIUM] CVE-2021-35539: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significant
nvd
CVE-2015-1380P4MEDIUMCVSS 5.0v11.22015-02-03
CVE-2015-1380 [MEDIUM] CWE-20 CVE-2015-1380: jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a cr
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
nvd
CVE-2015-3811P4MEDIUMCVSS 5.0v11.22015-05-26
CVE-2015-3811 [MEDIUM] CVE-2015-3811: epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x befo
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.
nvd
CVE-2015-0564P4MEDIUMCVSS 5.0v11.22015-01-10
CVE-2015-0564 [MEDIUM] CWE-119 CVE-2015-0564: Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wiresha
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that is improperly handled during decryption of an SSL session.
nvd
CVE-2014-6496P4MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6496 [MEDIUM] CVE-2014-6496: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
nvd
CVE-2016-2178P4MEDIUMCVSS 5.5v10v11.32016-06-20
CVE-2016-2178 [MEDIUM] CWE-203 CVE-2016-2178: The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ens
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
nvd
CVE-2018-2577P4MEDIUMCVSS 5.5v11.32018-01-18
CVE-2018-2577 [MEDIUM] CVE-2018-2577: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized acc
nvd
CVE-2016-0416P4MEDIUMCVSS 5.0v112016-01-21
CVE-2016-0416 [MEDIUM] CVE-2016-0416: Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via u
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to System Archive Utility.
nvd
CVE-2011-3201P4MEDIUMCVSS 4.3v11.22013-03-08
CVE-2011-3201 [MEDIUM] CWE-200 CVE-2011-3201: GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the a
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
nvd
CVE-2015-0448P4HIGHCVSS 7.2v11.22015-04-16
CVE-2015-0448 [HIGH] CVE-2015-0448: Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, i
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to ZFS File system.
nvd
CVE-2016-5358P4MEDIUMCVSS 5.9v11.32016-08-07
CVE-2016-5358 [MEDIUM] CWE-20 CVE-2016-5358: epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles th
epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2013-5611P4MEDIUMCVSS 5.8v11.32013-12-11
CVE-2013-5611 [MEDIUM] CVE-2013-5611: Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which
Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.
nvd
CVE-2015-4651P4MEDIUMCVSS 5.0v11.32015-07-22
CVE-2015-4651 [MEDIUM] CWE-399 CVE-2015-4651: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissect
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2015-2729P4MEDIUMCVSS 5.0v11.32015-07-06
CVE-2015-2729 [MEDIUM] CWE-119 CVE-2015-2729: The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Fire
The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecifi
nvd
CVE-2025-21551P4MEDIUMCVSS 6.0v112025-01-21
CVE-2025-21551 [MEDIUM] CWE-732 CVE-2025-21551: Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The suppor
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2011-3534P4MEDIUMCVSS 5.0v8v9+2 more2011-10-18
CVE-2011-3534 [MEDIUM] CVE-2011-3534: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affe
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network Status Monitor (statd).
nvd
CVE-2020-14758P4MEDIUMCVSS 5.6v112020-10-21
CVE-2020-14758 [MEDIUM] CVE-2020-14758: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the
nvd
CVE-2015-4816P4MEDIUMCVSS 4.0v11.32015-10-21
CVE-2015-4816 [MEDIUM] CVE-2015-4816: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd