Oracle Solaris vulnerabilities

549 known vulnerabilities affecting oracle/solaris.

Total CVEs
549
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
8
Severity breakdown
CRITICAL45HIGH116MEDIUM285LOW103

Vulnerabilities

Page 8 of 28
CVE-2017-5753MEDIUMCVSS 5.6PoCv10v11.32018-01-04
CVE-2017-5753 [MEDIUM] CWE-203 CVE-2017-5753: Systems with microprocessors utilizing speculative execution and branch prediction may allow unautho Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
nvd
CVE-2017-3632CRITICALCVSS 9.8v10v112017-08-08
CVE-2017-3632 [CRITICAL] CVE-2017-3632: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: CDE Calen Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: CDE Calendar). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. Note: CVE
nvd
CVE-2017-10042HIGHCVSS 7.5v10v112017-08-08
CVE-2017-10042 [HIGH] CVE-2017-10042: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: IKE). Sup Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: IKE). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via IKE to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or f
nvd
CVE-2017-10036HIGHCVSS 7.5v10v112017-08-08
CVE-2017-10036 [HIGH] CVE-2017-10036: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NFSv4). S Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: NFSv4). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFSv4 to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang
nvd
CVE-2017-10003MEDIUMCVSS 4.5v102017-08-08
CVE-2017-10003 [MEDIUM] CVE-2017-10003: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network S Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Network Services Library). The supported version that is affected is 10. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can resul
nvd
CVE-2017-10062MEDIUMCVSS 5.3v102017-08-08
CVE-2017-10062 [MEDIUM] CVE-2017-10062: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Oracle Ja Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Oracle Java Web Console). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result i
nvd
CVE-2017-10004MEDIUMCVSS 6.7v10v112017-08-08
CVE-2017-10004 [MEDIUM] CVE-2017-10004: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover
nvd
CVE-2017-10122LOWCVSS 1.8v10v112017-08-08
CVE-2017-10122 [LOW] CVE-2017-10122: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other
nvd
CVE-2017-10095LOWCVSS 3.3v112017-08-08
CVE-2017-10095 [LOW] CVE-2017-10095: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than the
nvd
CVE-2017-3629HIGHCVSS 7.8PoCv10v112017-06-22
CVE-2017-3629 [HIGH] CWE-119 CVE-2017-3629: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeov
nvd
CVE-2017-3631MEDIUMCVSS 5.3PoCv112017-06-22
CVE-2017-3631 [MEDIUM] CWE-119 CVE-2017-3631: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2017-3630MEDIUMCVSS 5.3PoCv10v112017-06-22
CVE-2017-3630 [MEDIUM] CWE-787 CVE-2017-3630: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unau
nvd
CVE-2017-3510CRITICALCVSS 9.6v11.32017-04-24
CVE-2017-3510 [CRITICAL] CVE-2017-3510: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris. While the vulnerability is in Solaris, attacks may
nvd
CVE-2017-3565HIGHCVSS 7.9v11.32017-04-24
CVE-2017-3565 [HIGH] CVE-2017-3565: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than th
nvd
CVE-2017-3564HIGHCVSS 8.2v11.32017-04-24
CVE-2017-3564 [HIGH] CVE-2017-3564: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than th
nvd
CVE-2017-3497HIGHCVSS 7.3v11.32017-04-24
CVE-2017-3497 [HIGH] CVE-2017-3497: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Ad Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2017-3622HIGHCVSS 7.8PoCv102017-04-24
CVE-2017-3622 [HIGH] CVE-2017-3622: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common De Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version that is affected is 10. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can r
nvd
CVE-2017-3516HIGHCVSS 7.7v11.32017-04-24
CVE-2017-3516 [HIGH] CVE-2017-3516: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zo Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris. While the vulnerability is in Solaris, attacks may sig
nvd
CVE-2017-3551MEDIUMCVSS 6.6v11.32017-04-24
CVE-2017-3551 [MEDIUM] CVE-2017-3551: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Libraries). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in
nvd
CVE-2017-3474LOWCVSS 3.3v11.32017-04-24
CVE-2017-3474 [LOW] CVE-2017-3474: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zone). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zone). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized read
nvd