Oracle Solaris vulnerabilities
552 known vulnerabilities affecting oracle/solaris.
Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH117MEDIUM286LOW103
Vulnerabilities
Page 19 of 28
CVE-2014-1480P4MEDIUMCVSS 4.3v11.32014-02-06
CVE-2014-1480 [MEDIUM] CWE-1021 CVE-2014-1480: The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not p
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
nvd
CVE-2015-4826P4MEDIUMCVSS 4.0v11.32015-10-21
CVE-2015-4826 [MEDIUM] CVE-2015-4826: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.
nvd
CVE-2020-14545P4MEDIUMCVSS 5.0v112020-07-15
CVE-2020-14545 [MEDIUM] CVE-2020-14545: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). Th
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a pers
nvd
CVE-2022-21416P4MEDIUMCVSS 5.0v112022-04-19
CVE-2022-21416 [MEDIUM] CVE-2022-21416: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported ve
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than th
nvd
CVE-2018-3265P4MEDIUMCVSS 4.9v11.32018-10-17
CVE-2018-3265 [MEDIUM] CVE-2018-3265: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). T
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2015-4484P4MEDIUMCVSS 5.0v11.32015-08-16
CVE-2015-4484 [MEDIUM] CWE-119 CVE-2015-4484: The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Fire
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.
nvd
CVE-2014-1500P4MEDIUMCVSS 5.0v11.32014-03-19
CVE-2014-1500 [MEDIUM] CWE-400 CVE-2014-1500: Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of se
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
nvd
CVE-2020-2680P4MEDIUMCVSS 6.0v112020-01-15
CVE-2020-2680 [MEDIUM] CVE-2020-2680: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantl
nvd
CVE-2021-35589P4MEDIUMCVSS 6.0v112021-10-20
CVE-2021-35589 [MEDIUM] CVE-2021-35589: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device drivers). The suppo
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device drivers). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may signif
nvd
CVE-2022-21493P4MEDIUMCVSS 5.9v112022-04-19
CVE-2022-21493 [MEDIUM] CVE-2022-21493: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported ver
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the
nvd
CVE-2014-1498P4MEDIUMCVSS 5.0v11.32014-03-19
CVE-2014-1498 [MEDIUM] CWE-347 CVE-2014-1498: The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.
nvd
CVE-2013-5612P4MEDIUMCVSS 4.3v11.32013-12-11
CVE-2013-5612 [MEDIUM] CWE-79 CVE-2013-5612: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 ma
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.
nvd
CVE-2015-2697P4MEDIUMCVSS 4.0v11.32015-11-09
CVE-2015-2697 [MEDIUM] CWE-125 CVE-2015-2697: The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
nvd
CVE-2015-0505P4LOWCVSS 3.5v11.32015-04-16
CVE-2015-0505 [LOW] CVE-2015-0505: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
nvd
CVE-2015-7830P4MEDIUMCVSS 4.3v11.32015-11-15
CVE-2015-7830 [MEDIUM] CWE-20 CVE-2015-7830: The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x
The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect free and application crash) via a crafted packet that triggers interface-filter copying.
nvd
CVE-2014-5353P4LOWCVSS 3.5v10v11.22014-12-16
CVE-2014-5353 [LOW] CWE-476 CVE-2014-5353: The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password
nvd
CVE-2015-6241P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6241 [MEDIUM] CWE-20 CVE-2015-6241: The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wiresh
The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2015-0499P4LOWCVSS 3.5v11.32015-04-16
CVE-2015-0499 [LOW] CVE-2015-0499: Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
nvd
CVE-2014-1499P4MEDIUMCVSS 4.3v11.32014-03-19
CVE-2014-1499 [MEDIUM] CVE-2014-1499: Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain nam
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
nvd
CVE-2026-21942P4MEDIUMCVSS 5.0v10v112026-01-20
CVE-2026-21942 [MEDIUM] CWE-400 CVE-2026-21942: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported v
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a per
nvd