Sun Opensolaris vulnerabilities

108 known vulnerabilities affecting sun/opensolaris.

Total CVEs
108
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH34MEDIUM61LOW6

Vulnerabilities

Page 1 of 6
CVE-2016-1291CRITICALCVSS 9.8vsnv_1242016-04-06
CVE-2016-1291 [CRITICAL] CWE-20 CVE-2016-1291: Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
nvd
CVE-2015-6313HIGHCVSS 7.5vsnv_1242016-04-06
CVE-2015-6313 [HIGH] CWE-399 CVE-2015-6313: Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv4
nvd
CVE-2016-1290HIGHCVSS 8.1vsnv_1242016-04-06
CVE-2016-1290 [HIGH] CWE-264 CVE-2016-1290: The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Networ The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
nvd
CVE-2016-1314MEDIUMCVSS 6.1vsnv_1242016-03-28
CVE-2016-1314 [MEDIUM] CWE-79 CVE-2016-1314: Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux80760.
nvd
CVE-2016-1349HIGHCVSS 7.5vsnv_1242016-03-26
CVE-2016-1349 [HIGH] CWE-399 CVE-2016-1349: The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
nvd
CVE-2016-1350HIGHCVSS 7.5vsnv_1242016-03-26
CVE-2016-1350 [HIGH] CWE-399 CVE-2016-1350: Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager all Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
nvd
CVE-2016-1348HIGHCVSS 7.5vsnv_1242016-03-26
CVE-2016-1348 [HIGH] CWE-399 CVE-2016-1348: Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.
nvd
CVE-2016-1344MEDIUMCVSS 5.9vsnv_1242016-03-26
CVE-2016-1344 [MEDIUM] CWE-399 CVE-2016-1344: The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote at The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
nvd
CVE-2016-1329CRITICALCVSS 9.8vsnv_1242016-03-03
CVE-2016-1329 [CRITICAL] CWE-287 CVE-2016-1329: Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5 Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.
nvd
CVE-2015-0718HIGHCVSS 7.5vsnv_1242016-03-03
CVE-2015-0718 [HIGH] CWE-399 CVE-2015-0718: Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Comp Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.
nvd
CVE-2016-1331MEDIUMCVSS 6.1vsnv_1242016-02-15
CVE-2016-1331 [MEDIUM] CWE-79 CVE-2016-1331: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) all Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.
nvd
CVE-2016-1319MEDIUMCVSS 5.3vsnv_1242016-02-09
CVE-2016-1319 [MEDIUM] CWE-200 CVE-2016-1319: Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.1290 Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via
nvd
CVE-2016-1302HIGHCVSS 8.8vsnv_1242016-02-07
CVE-2016-1302 [HIGH] CWE-284 CVE-2016-1302: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1 Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.
nvd
CVE-2016-1306MEDIUMCVSS 6.1vsnv_1242016-02-06
CVE-2016-1306 [MEDIUM] CWE-79 CVE-2016-1306: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attack Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466.
nvd
CVE-2016-1310MEDIUMCVSS 6.1vsnv_1242016-02-06
CVE-2016-1310 [MEDIUM] CWE-79 CVE-2016-1310: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attacke Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.
nvd
CVE-2015-6319CRITICALCVSS 9.8vsnv_1242016-01-27
CVE-2015-6319 [CRITICAL] CWE-89 CVE-2015-6319: SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows rem SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.
nvd
CVE-2008-7300HIGHCVSS 8.5vbuild_snv_39vbuild_snv_47+3 more2011-10-05
CVE-2008-7300 [HIGH] CWE-264 CVE-2008-7300: The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolari The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to the global zone.
nvd
CVE-2009-4774MEDIUMCVSS 4.0vsnv_49vsnv_50+67 more2010-04-21
CVE-2009-4774 [MEDIUM] CVE-2009-4774: Unspecified vulnerability in Sun Solaris 10 and OpenSolaris snv_49 through snv_117, when 64bit mode Unspecified vulnerability in Sun Solaris 10 and OpenSolaris snv_49 through snv_117, when 64bit mode is used on the Intel x86 platform and a Linux (lx) branded zone is configured, allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2007-6225.
nvd
CVE-2010-0558HIGHCVSS 7.5vsnv_77vsnv_78+53 more2010-02-05
CVE-2010-0558 [HIGH] CWE-16 CVE-2010-0558: The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an u The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.
nvd
CVE-2010-0559HIGHCVSS 7.5vsnv_91vsnv_92+39 more2010-02-05
CVE-2010-0559 [HIGH] CWE-16 CVE-2010-0559: The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an u The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.
nvd