Oracle Solaris vulnerabilities

549 known vulnerabilities affecting oracle/solaris.

Total CVEs
549
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
8
Severity breakdown
CRITICAL45HIGH116MEDIUM285LOW103

Vulnerabilities

Page 21 of 28
CVE-2014-9663HIGHCVSS 7.5v10.0v11.22015-02-08
CVE-2014-9663 [HIGH] CWE-119 CVE-2014-9663: The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2014-9660HIGHCVSS 7.5v10.0v11.22015-02-08
CVE-2014-9660 [HIGH] CWE-476 CVE-2014-9660: The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a m The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
nvd
CVE-2014-9659HIGHCVSS 7.5v10.0v11.22015-02-08
CVE-2014-9659 [HIGH] CVE-2014-9659: cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional h cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2
nvd
CVE-2014-9664MEDIUMCVSS 6.8v10.0v11.22015-02-08
CVE-2014-9664 [MEDIUM] CWE-119 CVE-2014-9664: FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which a FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
nvd
CVE-2014-9669MEDIUMCVSS 6.8v10.0v11.22015-02-08
CVE-2014-9669 [MEDIUM] CWE-125 CVE-2014-9669: Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2014-9666MEDIUMCVSS 6.8v10.0v11.22015-02-08
CVE-2014-9666 [MEDIUM] CWE-189 CVE-2014-9666: The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.
nvd
CVE-2014-9672MEDIUMCVSS 5.8v10.0v11.22015-02-08
CVE-2014-9672 [MEDIUM] CWE-119 CVE-2014-9672: Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.
nvd
CVE-2014-9671MEDIUMCVSS 4.3v10.0v11.22015-02-08
CVE-2014-9671 [MEDIUM] CVE-2014-9671: Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
nvd
CVE-2014-9670MEDIUMCVSS 4.3v10.0v11.22015-02-08
CVE-2014-9670 [MEDIUM] CWE-189 CVE-2014-9670: Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType be Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
nvd
CVE-2015-1380MEDIUMCVSS 5.0v11.22015-02-03
CVE-2015-1380 [MEDIUM] CWE-20 CVE-2015-1380: jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a cr jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
nvd
CVE-2015-0411HIGHCVSS 7.5v11.32015-01-21
CVE-2015-0411 [HIGH] CVE-2015-0411: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
nvd
CVE-2015-0381MEDIUMCVSS 4.3v11.32015-01-21
CVE-2015-0381 [MEDIUM] CVE-2015-0381: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.
nvd
CVE-2015-0382MEDIUMCVSS 4.3v11.32015-01-21
CVE-2015-0382 [MEDIUM] CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
nvd
CVE-2015-1038MEDIUMCVSS 5.8v10.0v11.22015-01-21
CVE-2015-1038 [MEDIUM] CWE-59 CVE-2015-1038: p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive. p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
nvd
CVE-2015-1196MEDIUMCVSS 4.3v11.22015-01-21
CVE-2015-1196 [MEDIUM] CWE-59 CVE-2015-1196: GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
nvd
CVE-2015-0432MEDIUMCVSS 4.0v11.32015-01-21
CVE-2015-0432 [MEDIUM] CVE-2015-0432: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
nvd
CVE-2015-0378LOWCVSS 2.1v112015-01-21
CVE-2015-0378 [LOW] CVE-2015-0378: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unk Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Libc.
nvd
CVE-2014-6568LOWCVSS 3.5v11.32015-01-21
CVE-2014-6568 [LOW] CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
nvd
CVE-2015-0374LOWCVSS 3.5v11.32015-01-21
CVE-2015-0374 [LOW] CVE-2015-0374: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
nvd
CVE-2015-0973HIGHCVSS 8.8v11.22015-01-18
CVE-2015-0973 [HIGH] CVE-2015-0973: Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x b Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.
nvd