cbcvebase.

Oracle Solaris vulnerabilities

551 known vulnerabilities affecting oracle/solaris.

Total CVEs
551
CISA KEV
6
actively exploited
Public exploits
29
Exploited in wild
10
Severity breakdown
CRITICAL46HIGH116MEDIUM286LOW103

Vulnerabilities

Page 9 of 28
CVE-2017-3564P3HIGHCVSS 8.2v11.32017-04-24
CVE-2017-3564 [HIGH] CVE-2017-3564: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than th
nvd
CVE-2015-0828P3MEDIUMCVSS 6.8v11.32015-02-25
CVE-2015-0828 [MEDIUM] CVE-2015-0828: Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36 Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.
nvd
CVE-2017-3565P3HIGHCVSS 7.9v11.32017-04-24
CVE-2017-3565 [HIGH] CVE-2017-3565: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). Th Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require human interaction from a person other than th
nvd
CVE-2016-0505P4MEDIUMCVSS 6.8v11.32016-01-21
CVE-2016-0505 [MEDIUM] CVE-2016-0505: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options.
nvd
CVE-2016-4956P4MEDIUMCVSS 5.3v10v11.32016-07-05
CVE-2016-4956 [MEDIUM] CVE-2016-4956: ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mod ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
nvd
CVE-2014-8094P4MEDIUMCVSS 6.5v10v11.22014-12-10
CVE-2014-8094 [MEDIUM] CWE-190 CVE-2014-8094: Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserv Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, which triggers an out-of-bounds read or write.
nvd
CVE-2016-5544P4HIGHCVSS 7.8v10v11.32016-10-25
CVE-2016-5544 [HIGH] CVE-2016-5544: Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect confidentia Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel/X86.
nvd
CVE-2020-2565P4HIGHCVSS 7.5v112020-01-15
CVE-2020-2565 [HIGH] CVE-2020-2565: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Consolidation Infrastructu Vulnerability in the Oracle Solaris product of Oracle Systems (component: Consolidation Infrastructure). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a p
nvd
CVE-2019-2804P4HIGHCVSS 7.3v10.0v11.42019-07-23
CVE-2019-2804 [HIGH] CVE-2019-2804: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Fi Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Filesystem). Supported versions that are affected are 11.4 and 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interact
nvd
CVE-2020-14724P4HIGHCVSS 7.3v112020-07-15
CVE-2020-14724 [HIGH] CVE-2020-14724: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). Th Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person o
nvd
CVE-2016-4955P4MEDIUMCVSS 5.9v10v11.32016-07-05
CVE-2016-4955 [MEDIUM] CWE-362 CVE-2016-4955: ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial o ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.
nvd
CVE-2015-2734P4CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2734 [CRITICAL] CWE-17 CVE-2015-2734: The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Fi The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2015-2738P4CRITICALCVSS 10.0v11.32015-07-06
CVE-2015-2738 [CRITICAL] CWE-17 CVE-2015-2738: The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
nvd
CVE-2015-2578P4HIGHCVSS 7.1v11.22015-04-16
CVE-2015-2578 [HIGH] CVE-2015-2578: Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap.
nvd
CVE-2016-3441P4HIGHCVSS 7.8v10v11.32016-04-21
CVE-2016-3441 [HIGH] CVE-2016-3441: Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect confidentia Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect confidentiality, integrity, and availability via vectors related to Filesystem.
nvd
CVE-2014-2436P4MEDIUMCVSS 6.5v11.32014-04-16
CVE-2014-2436 [MEDIUM] CVE-2014-2436: Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR.
nvd
CVE-2015-2568P4MEDIUMCVSS 5.0v11.32015-04-16
CVE-2015-2568 [MEDIUM] CVE-2015-2568: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2019-2820P4HIGHCVSS 7.3v11.42019-07-23
CVE-2019-2820 [HIGH] CVE-2019-2820: Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Gn Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Gnuplot). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from
nvd
CVE-2018-1165P4HIGHCVSS 7.0v112018-02-21
CVE-2018-1165 [HIGH] CWE-122 CVE-2018-1165: This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joye This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue result
nvd
CVE-2023-21984P4MEDIUMCVSS 6.5v112023-04-18
CVE-2023-21984 [MEDIUM] CVE-2023-21984: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries). The supporte Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently
nvd
Oracle Solaris vulnerabilities | cvebase