Oracle Solaris vulnerabilities

549 known vulnerabilities affecting oracle/solaris.

Total CVEs
549
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
8
Severity breakdown
CRITICAL45HIGH116MEDIUM285LOW103

Vulnerabilities

Page 23 of 28
CVE-2014-6507MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6507 [MEDIUM] CVE-2014-6507: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.
nvd
CVE-2014-6495MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6495 [MEDIUM] CVE-2014-6495: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.
nvd
CVE-2014-6469MEDIUMCVSS 6.8v11.32014-10-15
CVE-2014-6469 [MEDIUM] CVE-2014-6469: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER.
nvd
CVE-2014-6496MEDIUMCVSS 4.3v11.32014-10-15
CVE-2014-6496 [MEDIUM] CVE-2014-6496: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
nvd
CVE-2014-6463LOWCVSS 3.3v11.32014-10-15
CVE-2014-6463 [LOW] CVE-2014-6463: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML.
nvd
CVE-2014-6551LOWCVSS 2.1v11.32014-10-15
CVE-2014-6551 [LOW] CVE-2014-6551: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows lo Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN.
nvd
CVE-2014-0397CRITICALCVSS 10.0v10v11.12014-10-06
CVE-2014-0397 [CRITICAL] CWE-119 CVE-2014-0397: Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impa Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vectors related to "Buffer errors."
nvd
CVE-2014-6051HIGHCVSS 7.5v11.32014-09-30
CVE-2014-6051 [HIGH] CWE-189 CVE-2014-6051: Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
nvd
CVE-2014-5459LOWCVSS 3.6v11.22014-09-27
CVE-2014-5459 [LOW] CWE-59 CVE-2014-5459: The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrar The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.
nvd
CVE-2014-6270MEDIUMCVSS 6.8v11.22014-09-12
CVE-2014-6270 [MEDIUM] CWE-119 CVE-2014-6270: Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP po Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
nvd
CVE-2014-1563CRITICALCVSS 10.0v11.32014-09-03
CVE-2014-1563 [CRITICAL] CWE-416 CVE-2014-1563: Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox be Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle c
nvd
CVE-2014-1557CRITICALCVSS 9.3v11.32014-07-23
CVE-2014-1557 [CRITICAL] CWE-94 CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a hig
nvd
CVE-2014-1561MEDIUMCVSS 5.8v11.32014-07-23
CVE-2014-1561 [MEDIUM] CWE-264 CVE-2014-1561: Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customiz Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.
nvd
CVE-2014-3532LOWCVSS 2.1v11.32014-07-19
CVE-2014-3532 [LOW] CWE-20 CVE-2014-3532: dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows l dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.
nvd
CVE-2014-4260MEDIUMCVSS 5.5v11.32014-07-17
CVE-2014-4260 [MEDIUM] CVE-2014-4260: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
nvd
CVE-2014-4258MEDIUMCVSS 6.5v11.32014-07-17
CVE-2014-4258 [MEDIUM] CVE-2014-4258: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.
nvd
CVE-2014-4243LOWCVSS 2.8v11.32014-07-17
CVE-2014-4243 [LOW] CVE-2014-4243: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED.
nvd
CVE-2014-1542MEDIUMCVSS 6.8v11.32014-06-11
CVE-2014-1542 [MEDIUM] CWE-119 CVE-2014-1542: Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 all Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.
nvd
CVE-2011-2198LOWCVSS 3.5v11.22014-05-21
CVE-2011-2198 [LOW] CWE-20 CVE-2011-2198: The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remo The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing the string "\033[100000000000000000@".
nvd
CVE-2014-1528CRITICALCVSS 10.0v11.32014-04-30
CVE-2014-1528 [CRITICAL] CWE-119 CVE-2014-1528: The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and Se The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.
nvd