Oracle Solaris vulnerabilities
552 known vulnerabilities affecting oracle/solaris.
Total CVEs
552
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH117MEDIUM286LOW103
Vulnerabilities
Page 22 of 28
CVE-2015-4864P4LOWCVSS 3.5v11.32015-10-21
CVE-2015-4864 [LOW] CVE-2015-4864: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2010-3507P4MEDIUMCVSS 6.6v8v9+1 more2010-10-14
CVE-2010-3507 [MEDIUM] CVE-2010-3507: Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentialit
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Live Upgrade.
nvd
CVE-2016-0609P4LOWCVSS 1.7v11.32016-01-21
CVE-2016-0609 [LOW] CVE-2016-0609: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.
nvd
CVE-2016-3453P4MEDIUMCVSS 5.5v102016-07-21
CVE-2016-3453 [MEDIUM] CVE-2016-3453: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vec
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to Kernel.
nvd
CVE-2020-14537P4MEDIUMCVSS 5.5v112020-07-15
CVE-2020-14537 [MEDIUM] CWE-404 CVE-2020-14537: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Packaging Scripts). The su
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Packaging Scripts). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a p
nvd
CVE-2016-5576P4MEDIUMCVSS 5.5v11.32016-10-25
CVE-2016-5576 [MEDIUM] CWE-284 CVE-2016-5576: Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via v
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel Zones.
nvd
CVE-2016-3465P4MEDIUMCVSS 5.5v11.32016-04-21
CVE-2016-3465 [MEDIUM] CVE-2016-3465: Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availabilit
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via vectors related to ZFS.
nvd
CVE-2013-3793P4MEDIUMCVSS 4.0v11.32013-07-17
CVE-2013-3793 [MEDIUM] CVE-2013-3793: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
nvd
CVE-2013-3794P4MEDIUMCVSS 4.0v11.32013-07-17
CVE-2013-3794 [MEDIUM] CVE-2013-3794: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
nvd
CVE-2015-4861P4LOWCVSS 3.5v11.32015-10-21
CVE-2015-4861 [LOW] CVE-2015-4861: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2013-2376P4MEDIUMCVSS 4.0v11.32013-04-17
CVE-2013-2376 [MEDIUM] CVE-2013-2376: Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote au
Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
nvd
CVE-2014-2430P4LOWCVSS 3.5v11.32014-04-16
CVE-2014-2430 [LOW] CVE-2014-2430: Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema.
nvd
CVE-2020-2664P4MEDIUMCVSS 4.6v112020-01-15
CVE-2020-2664 [MEDIUM] CVE-2020-2664: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than t
nvd
CVE-2015-4482P4MEDIUMCVSS 4.6v11.32015-08-16
CVE-2015-4482 [MEDIUM] CWE-119 CVE-2015-4482: mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows loc
mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (aka MAR) file.
nvd
CVE-2018-2903P4MEDIUMCVSS 4.4v10.0v11.32018-07-18
CVE-2018-2903 [MEDIUM] CVE-2018-2903: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2018-3264P4MEDIUMCVSS 4.4v11.32018-10-17
CVE-2018-3264 [MEDIUM] CVE-2018-3264: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized upd
nvd
CVE-2014-5459P4LOWCVSS 3.6v11.22014-09-27
CVE-2014-5459 [LOW] CWE-59 CVE-2014-5459: The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrar
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
nvd
CVE-2015-4792P4LOWCVSS 1.7v11.32015-10-21
CVE-2015-4792 [LOW] CVE-2015-4792: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.
nvd
CVE-2014-1489P4MEDIUMCVSS 4.3v11.32014-02-06
CVE-2014-1489 [MEDIUM] CWE-264 CVE-2014-1489: Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on oth
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
nvd
CVE-2013-3805P4MEDIUMCVSS 4.0v11.32013-07-17
CVE-2013-3805 [MEDIUM] CVE-2013-3805: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements.
nvd