Oracle Solaris vulnerabilities
552 known vulnerabilities affecting oracle/solaris.
Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH117MEDIUM286LOW103
Vulnerabilities
Page 17 of 28
CVE-2015-2643P4MEDIUMCVSS 4.0v11.32015-07-16
CVE-2015-2643 [MEDIUM] CVE-2015-2643: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
nvd
CVE-2016-0596P4MEDIUMCVSS 4.0v11.32016-01-21
CVE-2016-0596 [MEDIUM] CVE-2016-0596: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB befo
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-0597P4MEDIUMCVSS 4.0v11.32016-01-21
CVE-2016-0597 [MEDIUM] CVE-2016-0597: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-4802P4MEDIUMCVSS 4.0v11.32015-10-21
CVE-2015-4802 [MEDIUM] CVE-2015-4802: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.
nvd
CVE-2013-6672P4MEDIUMCVSS 4.3v11.32013-12-11
CVE-2013-6672 [MEDIUM] CWE-200 CVE-2013-6672: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
nvd
CVE-2014-1484P4MEDIUMCVSS 5.0v11.32014-02-06
CVE-2014-1484 [MEDIUM] CWE-200 CVE-2014-1484: Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.
nvd
CVE-2015-2721P4MEDIUMCVSS 4.3v11.32015-07-06
CVE-2015-2721 [MEDIUM] CWE-310 CVE-2015-2721: Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by b
nvd
CVE-2014-1527P4MEDIUMCVSS 5.0v11.32014-04-30
CVE-2014-1527 [MEDIUM] CVE-2014-1527: Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted
Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.
nvd
CVE-2015-3219P4MEDIUMCVSS 4.3v11.22015-08-20
CVE-2015-3219 [MEDIUM] CWE-79 CVE-2015-3219: Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the help_text attribute in the Field class.
nvd
CVE-2015-4858P4MEDIUMCVSS 4.0v11.32015-10-21
CVE-2015-4858 [MEDIUM] CVE-2015-4858: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913.
nvd
CVE-2013-5614P4MEDIUMCVSS 4.3v11.32013-12-11
CVE-2013-5614 [MEDIUM] CWE-1021 CVE-2013-5614: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
nvd
CVE-2015-4830P4MEDIUMCVSS 4.0v11.32015-10-21
CVE-2015-4830 [MEDIUM] CVE-2015-4830: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2016-0623P4MEDIUMCVSS 4.7v11.32016-04-21
CVE-2016-0623 [MEDIUM] CVE-2016-0623: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect integrity via
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect integrity via vectors related to the Automated Installer sub-component.
nvd
CVE-2018-3269P4MEDIUMCVSS 4.3v11.32018-10-17
CVE-2018-3269 [MEDIUM] CVE-2018-3269: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Serve
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: SMB Server). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial
nvd
CVE-2016-0535P4MEDIUMCVSS 4.3v10v112016-01-21
CVE-2016-0535 [MEDIUM] CVE-2016-0535: Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availabi
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to RPC.
nvd
CVE-2015-4483P4MEDIUMCVSS 4.3v11.32015-08-16
CVE-2015-4483 [MEDIUM] CWE-264 CVE-2015-4483: Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection
Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.
nvd
CVE-2014-6568P4LOWCVSS 3.5v11.32015-01-21
CVE-2014-6568 [LOW] CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
nvd
CVE-2016-0669P4MEDIUMCVSS 6.0v11.32016-04-21
CVE-2016-0669 [MEDIUM] CVE-2016-0669: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and avai
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Fwflash.
nvd
CVE-2015-2582P4MEDIUMCVSS 4.0v11.32015-07-16
CVE-2015-2582 [MEDIUM] CVE-2015-2582: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
nvd
CVE-2015-2648P4MEDIUMCVSS 4.0v11.32015-07-16
CVE-2015-2648 [MEDIUM] CVE-2015-2648: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd