cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 7 of 28
CVE-2024-21059P3HIGHCVSS 7.8v112024-04-16
CVE-2024-21059 [HIGH] CWE-269 CVE-2024-21059: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significa
nvd
CVE-2015-2725P3CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2725 [CRITICAL] CWE-119 CVE-2015-2725: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2014-1563P3CRITICALCVSS 10.0v11.32014-09-03
CVE-2014-1563 [CRITICAL] CWE-416 CVE-2014-1563: Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox be Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle c
nvd
CVE-2014-1507P3CRITICALCVSS 9.3v11.32014-03-19
CVE-2014-1507 [CRITICAL] CWE-22 CVE-2014-1507: Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.
nvd
CVE-2015-8126P3HIGHCVSS 7.5v11.32015-11-13
CVE-2015-8126 [HIGH] CWE-120 CVE-2015-8126: Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1. Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value
nvd
CVE-2015-0829P3MEDIUMCVSS 6.8v11.32015-02-25
CVE-2015-0829 [MEDIUM] CWE-119 CVE-2015-0829: Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
nvd
CVE-2017-3516P3HIGHCVSS 7.7v11.32017-04-24
CVE-2017-3516 [HIGH] CVE-2017-3516: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris. While the vulnerability is in Solaris, attacks may sig
nvd
CVE-2016-6491P3HIGHCVSS 8.8v10.0v11.32016-12-13
CVE-2016-6491 [HIGH] CWE-125 CVE-2016-6491: Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5 Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.
nvd
CVE-2015-2735P3CRITICALCVSS 9.3v11.32015-07-06
CVE-2015-2735 [CRITICAL] CWE-17 CVE-2015-2735: nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
nvd
CVE-2020-2851P3HIGHCVSS 7.8v10v112020-04-15
CVE-2020-2851 [HIGH] CVE-2020-2851: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, att
nvd
CVE-2021-2167P3HIGHCVSS 7.8v102021-04-22
CVE-2021-2167 [HIGH] CVE-2021-2167: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in ta
nvd
CVE-2019-2541P3HIGHCVSS 7.5v102019-01-16
CVE-2019-2541 [HIGH] CVE-2019-2541: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: DH Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: DHCP Client). The supported version that is affected is 10. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Solaris executes to compromise Oracle Solaris.
nvd
CVE-2015-4491P3MEDIUMCVSS 6.8v10v11.32015-08-16
CVE-2015-4491 [MEDIUM] CWE-189 CVE-2015-4491: Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, a Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash
nvd
CVE-2015-1038P3MEDIUMCVSS 5.8v10.0v11.22015-01-21
CVE-2015-1038 [MEDIUM] CWE-59 CVE-2015-1038: p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive. p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
nvd
CVE-2020-12243P3HIGHCVSS 7.5v10v112020-04-28
CVE-2020-12243 [HIGH] CWE-674 CVE-2020-12243: In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).
nvd
CVE-2014-1494P3CRITICALCVSS 9.3v11.32014-03-19
CVE-2014-1494 [CRITICAL] CVE-2014-1494: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMon Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2014-1542P3MEDIUMCVSS 6.8v11.32014-06-11
CVE-2014-1542 [MEDIUM] CWE-119 CVE-2014-1542: Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 all Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.
nvd
CVE-2014-0397P3CRITICALCVSS 10.0v10v11.12014-10-06
CVE-2014-0397 [CRITICAL] CWE-119 CVE-2014-0397: Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impa Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vectors related to "Buffer errors."
nvd
CVE-2015-1283P3MEDIUMCVSS 6.8v10v11.32015-07-23
CVE-2015-1283 [MEDIUM] CWE-190 CVE-2015-1283: Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google C Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
nvd
CVE-2015-4481P4LOWCVSS 3.3PoCv11.32015-08-16
CVE-2015-4481 [LOW] CWE-362 CVE-2015-4481: Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38. Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.
nvd
Oracle Solaris vulnerabilities | cvebase