cbcvebase.

Oracle Solaris vulnerabilities

552 known vulnerabilities affecting oracle/solaris.

Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH117MEDIUM286LOW103

Vulnerabilities

Page 20 of 28
CVE-2011-2304P4MEDIUMCVSS 4.3v102011-10-18
CVE-2011-2304 [MEDIUM] CVE-2011-2304: Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality, re Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality, related to Network Services Library (libnsl).
nvd
CVE-2015-3455P4LOWCVSS 2.6v11.22015-05-18
CVE-2015-3455 [LOW] CWE-20 CVE-2015-3455: Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when co Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
nvd
CVE-2015-0374P4LOWCVSS 3.5v11.32015-01-21
CVE-2015-0374 [LOW] CVE-2015-0374: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
nvd
CVE-2018-2563P4MEDIUMCVSS 4.2v10.0v11.32018-04-19
CVE-2018-2563 [MEDIUM] CVE-2018-2563: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LDAP Libr Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: LDAP Library). Supported versions that are affected are 10 and 11.3. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2019-2787P4MEDIUMCVSS 4.2v10.0v11.42019-07-23
CVE-2019-2787 [MEDIUM] CVE-2019-2787: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Au Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Automount). Supported versions that are affected are 11.4 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via NFS to compromise Oracle Solaris. Successful attacks require human interaction from a person other than th
nvd
CVE-2015-4837P4MEDIUMCVSS 6.6v11.22015-10-21
CVE-2015-4837 [MEDIUM] CVE-2015-4837: Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, i Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Security.
nvd
CVE-2015-4817P4MEDIUMCVSS 6.2v11.22015-10-21
CVE-2015-4817 [MEDIUM] CVE-2015-4817: Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, i Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel Zones virtualized NIC driver.
nvd
CVE-2014-9670P4MEDIUMCVSS 4.3v10.0v11.22015-02-08
CVE-2014-9670 [MEDIUM] CWE-189 CVE-2014-9670: Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType be Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
nvd
CVE-2014-9671P4MEDIUMCVSS 4.3v10.0v11.22015-02-08
CVE-2014-9671 [MEDIUM] CVE-2014-9671: Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
nvd
CVE-2016-3497P4MEDIUMCVSS 5.5v11.32016-07-21
CVE-2016-3497 [MEDIUM] CVE-2016-3497: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via v Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel, a different vulnerability than CVE-2016-5469 and CVE-2016-5471.
nvd
CVE-2016-5469P4MEDIUMCVSS 5.5v11.32016-07-21
CVE-2016-5469 [MEDIUM] CVE-2016-5469: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via v Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel, a different vulnerability than CVE-2016-3497 and CVE-2016-5471.
nvd
CVE-2016-5471P4MEDIUMCVSS 5.5v11.32016-07-21
CVE-2016-5471 [MEDIUM] CVE-2016-5471: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via v Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel, a different vulnerability than CVE-2016-3497 and CVE-2016-5469.
nvd
CVE-2025-53070P4MEDIUMCVSS 5.5v112025-10-21
CVE-2025-53070 [MEDIUM] CWE-267 CVE-2025-53070: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The support Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person oth
nvd
CVE-2015-6246P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6246 [MEDIUM] CWE-20 CVE-2015-6246: The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2015-6249P4MEDIUMCVSS 4.3v11.32015-08-24
CVE-2015-6249 [MEDIUM] CWE-20 CVE-2015-6249: The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissect The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2015-3646P4MEDIUMCVSS 4.0v11.22015-05-12
CVE-2015-3646 [MEDIUM] CWE-200 CVE-2015-3646: OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
nvd
CVE-2015-2742P4MEDIUMCVSS 4.3v11.32015-07-06
CVE-2015-2742 [MEDIUM] CWE-200 CVE-2015-2742: Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of cras Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.
nvd
CVE-2022-21263P4MEDIUMCVSS 4.8v112022-01-19
CVE-2022-21263 [MEDIUM] CVE-2022-21263: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fault Management Architect Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fault Management Architecture). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from
nvd
CVE-2016-0606P4LOWCVSS 3.5v11.32016-01-21
CVE-2016-0606 [LOW] CVE-2016-0606: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
nvd
CVE-2015-4737P4LOWCVSS 3.5v11.32015-07-16
CVE-2015-4737 [LOW] CVE-2015-4737: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Pluggable Auth.
nvd
Oracle Solaris vulnerabilities | cvebase