cbcvebase.

Oracle Solaris vulnerabilities

552 known vulnerabilities affecting oracle/solaris.

Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH117MEDIUM286LOW103

Vulnerabilities

Page 21 of 28
CVE-2015-4913P4LOWCVSS 3.5v11.32015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2015-2741P4MEDIUMCVSS 4.3v11.32015-07-06
CVE-2015-2741 [MEDIUM] CWE-310 CVE-2015-2741: Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforc Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname f
nvd
CVE-2017-10003P4MEDIUMCVSS 4.5v102017-08-08
CVE-2017-10003 [MEDIUM] CVE-2017-10003: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network S Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network Services Library). The supported version that is affected is 10. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can resul
nvd
CVE-2020-2656P4MEDIUMCVSS 4.4v10v112020-01-15
CVE-2020-2656 [MEDIUM] CVE-2020-2656: Vulnerability in the Oracle Solaris product of Oracle Systems (component: X Window System). Supporte Vulnerability in the Oracle Solaris product of Oracle Systems (component: X Window System). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2015-2922P4LOWCVSS 3.3v11.32015-05-27
CVE-2015-2922 [LOW] CWE-17 CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol impl The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
nvd
CVE-2015-4820P4MEDIUMCVSS 6.2v11.22015-10-21
CVE-2015-4820 [MEDIUM] CVE-2015-4820: Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, i Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2015-4907.
nvd
CVE-2016-0418P4MEDIUMCVSS 6.1v112016-01-21
CVE-2016-0418 [MEDIUM] CVE-2016-0418: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, int Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0414.
nvd
CVE-2016-3462P4MEDIUMCVSS 5.5v11.32016-04-21
CVE-2016-3462 [MEDIUM] CVE-2016-3462: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via v Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Network Configuration Service.
nvd
CVE-2009-2857P4MEDIUMCVSS 5.5v8v9+1 more2009-08-19
CVE-2009-2857 [MEDIUM] CWE-667 CVE-2009-2857: The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle int The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.
nvd
CVE-2018-3271P4MEDIUMCVSS 5.3v11.32018-10-17
CVE-2018-3271 [MEDIUM] CVE-2018-3271: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. While the vulnerability is in Solaris, attacks may significan
nvd
CVE-2014-2419P4MEDIUMCVSS 4.0v11.32014-04-16
CVE-2014-2419 [MEDIUM] CVE-2014-2419: Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.
nvd
CVE-2018-2808P4MEDIUMCVSS 5.0v11.32018-04-19
CVE-2018-2808 [MEDIUM] CVE-2018-2808: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than t
nvd
CVE-2018-2560P4MEDIUMCVSS 5.0v11.32018-01-18
CVE-2018-2560 [MEDIUM] CVE-2018-2560: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other tha
nvd
CVE-2020-2647P4MEDIUMCVSS 5.0v10v112020-01-15
CVE-2020-2647 [MEDIUM] CVE-2020-2647: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). Supported version Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than
nvd
CVE-2013-3809P4MEDIUMCVSS 4.0v11.32013-07-17
CVE-2013-3809 [MEDIUM] CVE-2013-3809: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log.
nvd
CVE-2016-0598P4LOWCVSS 3.5v11.32016-01-21
CVE-2016-0598 [LOW] CVE-2016-0598: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-0608P4LOWCVSS 3.5v11.32016-01-21
CVE-2016-0608 [LOW] CVE-2016-0608: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF.
nvd
CVE-2016-0600P4LOWCVSS 3.5v11.32016-01-21
CVE-2016-0600 [LOW] CVE-2016-0600: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2009-2282P4MEDIUMCVSS 4.6v102009-07-01
CVE-2009-2282 [MEDIUM] CWE-862 CVE-2009-2282: The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10 The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.
nvd
CVE-2014-2431P4LOWCVSS 2.6v11.32014-04-16
CVE-2014-2431 [LOW] CVE-2014-2431: Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect availability via unknown vectors related to Options.
nvd
Oracle Solaris vulnerabilities | cvebase