cbcvebase.

Oracle Solaris vulnerabilities

552 known vulnerabilities affecting oracle/solaris.

Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH117MEDIUM286LOW103

Vulnerabilities

Page 18 of 28
CVE-2016-5452P4MEDIUMCVSS 5.5v11.32016-07-21
CVE-2016-5452 [MEDIUM] CVE-2016-5452: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality vi Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality via vectors related to Verified Boot.
nvd
CVE-2020-14754P4MEDIUMCVSS 5.5v112020-10-21
CVE-2020-14754 [MEDIUM] CVE-2020-14754: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized a
nvd
CVE-2015-4752P4MEDIUMCVSS 4.0v11.32015-07-16
CVE-2015-4752 [MEDIUM] CVE-2015-4752: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S.
nvd
CVE-2021-43395P4MEDIUMCVSS 5.5v10v112022-12-26
CVE-2021-43395 [MEDIUM] CWE-667 CVE-2021-43395: An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is also affected.
nvd
CVE-2022-21375P4MEDIUMCVSS 5.5v112022-01-19
CVE-2022-21375 [MEDIUM] CVE-2022-21375: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2015-6244P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6244 [MEDIUM] CWE-20 CVE-2015-6244: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector i The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2022-21463P4MEDIUMCVSS 5.5v112022-04-19
CVE-2022-21463 [MEDIUM] CVE-2022-21463: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2022-39417P4MEDIUMCVSS 5.5v112022-10-18
CVE-2022-39417 [MEDIUM] CVE-2022-39417: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized a
nvd
CVE-2022-21533P4MEDIUMCVSS 5.5v112022-07-19
CVE-2022-21533 [MEDIUM] CVE-2022-21533: Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMB Server). The supported Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMB Server). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized a
nvd
CVE-2022-39401P4MEDIUMCVSS 5.5v112022-10-18
CVE-2022-39401 [MEDIUM] CVE-2022-39401: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2015-0432P4MEDIUMCVSS 4.0v11.32015-01-21
CVE-2015-0432 [MEDIUM] CVE-2015-0432: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
nvd
CVE-2023-22129P4MEDIUMCVSS 5.5v112023-10-17
CVE-2023-22129 [MEDIUM] CVE-2023-22129: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2024-20946P4MEDIUMCVSS 5.5v112024-01-16
CVE-2024-20946 [MEDIUM] CVE-2024-20946: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported v Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2016-0616P4MEDIUMCVSS 4.0v11.32016-01-21
CVE-2016-0616 [MEDIUM] CVE-2016-0616: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x befor Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-6248P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6248 [MEDIUM] CWE-20 CVE-2015-6248: The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x befor The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2015-6243P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6243 [MEDIUM] CWE-20 CVE-2015-6243: The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles tab The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1) dissector_get_string_handle and (2) dissector_get_default_string_handle functions.
nvd
CVE-2015-4490P4MEDIUMCVSS 4.3v11.32015-08-16
CVE-2015-4490 [MEDIUM] CWE-79 CVE-2015-4490: The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 doe The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by lev
nvd
CVE-2015-4815P4MEDIUMCVSS 4.0v11.32015-10-21
CVE-2015-4815 [MEDIUM] CVE-2015-4815: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.
nvd
CVE-2016-5487P4MEDIUMCVSS 5.3v11.32016-10-25
CVE-2016-5487 [MEDIUM] CVE-2016-5487: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality, i Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2015-6242P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6242 [MEDIUM] CWE-20 CVE-2015-6242: The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block alloc The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect
nvd
Oracle Solaris vulnerabilities | cvebase