Oracle Solaris vulnerabilities
551 known vulnerabilities affecting oracle/solaris.
Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103
Vulnerabilities
Page 16 of 28
CVE-2018-12207P4MEDIUMCVSS 6.5v112019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2016-5454P4MEDIUMCVSS 6.4v11.32016-07-21
CVE-2016-5454 [MEDIUM] CVE-2016-5454: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and avai
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Verified Boot.
nvd
CVE-2018-3272P4MEDIUMCVSS 6.2v11.32018-10-17
CVE-2018-3272 [MEDIUM] CVE-2018-3272: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones Virtualized NIC Driver). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability
nvd
CVE-2015-2317P4MEDIUMCVSS 4.3v11.22015-03-25
CVE-2015-2317 [MEDIUM] CWE-79 CVE-2015-2317: The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x befor
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
nvd
CVE-2015-0433P4MEDIUMCVSS 4.0v11.32015-04-16
CVE-2015-0433 [MEDIUM] CVE-2015-0433: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
nvd
CVE-2014-8124P4MEDIUMCVSS 5.0v11.22014-12-12
CVE-2014-8124 [MEDIUM] CWE-400 CVE-2014-8124: OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
nvd
CVE-2015-2571P4MEDIUMCVSS 4.0v11.32015-04-16
CVE-2015-2571 [MEDIUM] CVE-2015-2571: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
CVE-2015-2573P4MEDIUMCVSS 4.0v11.32015-04-16
CVE-2015-2573 [MEDIUM] CVE-2015-2573: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
nvd
CVE-2014-1483P4MEDIUMCVSS 5.0v11.32014-02-06
CVE-2014-1483 [MEDIUM] CWE-1021 CVE-2014-1483: Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Orig
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
nvd
CVE-2017-3276P4MEDIUMCVSS 5.7v11.32017-01-27
CVE-2017-3276 [MEDIUM] CVE-2017-3276: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerabi
nvd
CVE-2015-2730P4MEDIUMCVSS 4.3v11.32015-07-06
CVE-2015-2730 [MEDIUM] CWE-310 CVE-2015-2730: Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firef
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via unspecified vectors.
nvd
CVE-2014-6495P4MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6495 [MEDIUM] CVE-2014-6495: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.
nvd
CVE-2015-6245P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6245 [MEDIUM] CWE-20 CVE-2015-6245: epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 u
epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
nvd
CVE-2017-10062P4MEDIUMCVSS 5.3v102017-08-08
CVE-2017-10062 [MEDIUM] CVE-2017-10062: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Oracle Ja
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Oracle Java Web Console). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result i
nvd
CVE-2019-2765P4MEDIUMCVSS 5.3v10v112019-10-16
CVE-2019-2765 [MEDIUM] CVE-2019-2765: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported ver
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may signi
nvd
CVE-2015-6247P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6247 [MEDIUM] CWE-20 CVE-2015-6247: The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow di
The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
nvd
CVE-2014-6478P4MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6478 [MEDIUM] CVE-2014-6478: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.
nvd
CVE-2012-0876P4MEDIUMCVSS 4.3v11.32012-07-03
CVE-2012-0876 [MEDIUM] CWE-400 CVE-2012-0876: The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the abili
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.
nvd
CVE-2016-5606P4MEDIUMCVSS 6.1v11.32016-10-25
CVE-2016-5606 [MEDIUM] CWE-284 CVE-2016-5606: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and avai
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Kernel Zones.
nvd
CVE-2015-2643P4MEDIUMCVSS 4.0v11.32015-07-16
CVE-2015-2643 [MEDIUM] CVE-2015-2643: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd