cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 5 of 28
CVE-2022-21524P3HIGHCVSS 7.6v112022-07-19
CVE-2022-21524 [HIGH] CVE-2022-21524: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently
nvd
CVE-2015-4486P3CRITICALCVSS 10.0v11.32015-08-16
CVE-2015-4486 [CRITICAL] CWE-119 CVE-2015-4486: The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data.
nvd
CVE-2016-5687P3CRITICALCVSS 9.8v11.32016-12-13
CVE-2016-5687 [CRITICAL] CWE-125 CVE-2016-5687: The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 al The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.
nvd
CVE-2019-2844P3HIGHCVSS 8.8v11.42019-07-23
CVE-2019-2844 [HIGH] CVE-2019-2844: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LD Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: LDAP Client Tools). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Sol
nvd
CVE-2019-2832P3HIGHCVSS 8.8v102019-07-23
CVE-2019-2832 [HIGH] CVE-2019-2832: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Co Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Ora
nvd
CVE-2015-4496P3CRITICALCVSS 9.3v11.32015-08-16
CVE-2015-4496 [CRITICAL] CVE-2015-4496: Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers t Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
nvd
CVE-2015-2155P3HIGHCVSS 7.5v11.22015-03-24
CVE-2015-2155 [HIGH] CVE-2015-2155: The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (cras The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2015-2716P3HIGHCVSS 7.5v11.32015-05-14
CVE-2015-2716 [HIGH] CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
nvd
CVE-2008-4609P3HIGHCVSS 7.1v8v9+1 more2008-10-20
CVE-2008-4609 [HIGH] CWE-16 CVE-2008-4609: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cis The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
nvd
CVE-2015-3330P3MEDIUMCVSS 6.8v11.22015-06-09
CVE-2015-3330 [MEDIUM] CWE-20 CVE-2015-3330: The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5. The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."
nvd
CVE-2014-6500P3HIGHCVSS 7.5v11.32014-10-15
CVE-2014-6500 [HIGH] CVE-2014-6500: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.
nvd
CVE-2014-6491P3HIGHCVSS 7.5v11.32014-10-15
CVE-2014-6491 [HIGH] CVE-2014-6491: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.
nvd
CVE-2018-2718P3HIGHCVSS 7.5v10.0v11.32018-04-19
CVE-2018-2718 [HIGH] CVE-2018-2718: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Sup Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or f
nvd
CVE-2018-2764P3HIGHCVSS 7.5v10v11.32018-04-19
CVE-2018-2764 [HIGH] CVE-2018-2764: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or
nvd
CVE-2017-10042P3HIGHCVSS 7.5v10v112017-08-08
CVE-2017-10042 [HIGH] CVE-2017-10042: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: IKE). Sup Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: IKE). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via IKE to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or f
nvd
CVE-2017-10036P3HIGHCVSS 7.5v10v112017-08-08
CVE-2017-10036 [HIGH] CVE-2017-10036: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NFSv4). S Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NFSv4). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFSv4 to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang
nvd
CVE-2014-1485P3HIGHCVSS 7.5v11.32014-02-06
CVE-2014-1485 [HIGH] CVE-2014-1485: The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
nvd
CVE-2010-3503P4MEDIUMCVSS 6.3PoCv102010-10-14
CVE-2010-3503 [MEDIUM] CVE-2010-3503: Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confiden Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrity via unknown vectors related to su.
nvd
CVE-2015-1351P3HIGHCVSS 7.5v11.22015-03-30
CVE-2015-1351 [HIGH] CWE-416 CVE-2015-1351: Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcac Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-2437P3HIGHCVSS 7.5v112019-01-16
CVE-2019-2437 [HIGH] CVE-2019-2437: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Ke Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd