← Back

Solaris

solaris

Vendor: Oracle • 555 CVEs

CVEs (555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Solaris
May 6, 2026
Jul 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel, a different vulnerability than CVE-2016-5469 and CVE-2016-5471.
1Oracle
1Solaris
May 6, 2026
Jul 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to Kernel.
8Apache
CanonicalDebian+5 more
20Communications User Data Repository
Debian LinuxEnterprise Linux Desktop+17 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remot...Show more
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.Show less
5Novell
NtpOpensuse+2 more
9Leap
Linux Enterprise DesktopLinux Enterprise Server+6 more
May 6, 2026
Jul 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
6Novell
NtpOpensuse+3 more
10Leap
Linux Enterprise DesktopLinux Enterprise Server+7 more
May 6, 2026
Jul 5, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete...Show more
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.Show less
6Novell
NtpOpensuse+3 more
10Leap
Linux Enterprise DesktopLinux Enterprise Server+7 more
May 6, 2026
Jul 5, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet wit...Show more
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.Show less
5Ntp
OpensuseOracle+2 more
12Leap
Linux Enterprise DesktopLinux Enterprise Server+9 more
May 6, 2026
Jul 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a...Show more
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.Show less
5Ntp
OpensuseOracle+2 more
12Leap
Linux Enterprise DesktopLinux Enterprise Server+9 more
May 6, 2026
Jul 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
4Canonical
GnuOracle+1 more
4Pan Os
SolarisUbuntu Linux+1 more
May 6, 2026
Jun 30, 2016
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
6Canonical
DebianNodejs+3 more
7Debian Linux
LinuxLinux Enterprise+4 more
May 6, 2026
Jun 20, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timin...Show more
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.Show less
3Hp
OpensslOracle
6Icewall Mcrp
Icewall SsoIcewall Sso Agent Option+3 more
May 6, 2026
Jun 20, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspec...Show more
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.Show less
7Canonical
DebianGraphicsmagick+4 more
14Debian Linux
GraphicsmagickImagemagick+11 more
May 6, 2026
Jun 10, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
7Canonical
DebianHp+4 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+11 more
May 6, 2026
May 17, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and applicatio...Show more
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.Show less
6Canonical
ImagemagickOpensuse+3 more
30Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 more
Apr 22, 2026
May 5, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
6Canonical
ImagemagickOpensuse+3 more
30Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux For Ibm Z Systems+27 more
Apr 22, 2026
May 5, 2016
N/A· v4
5.5 MEDIUM· v3
5.8 MEDIUM· v2
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
3Debian
OracleWireshark
3Debian Linux
SolarisWireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecif...Show more
Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a packet.Show less
3Debian
OracleWireshark
3Debian Linux
SolarisWireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service...Show more
epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.Show less
3Debian
OracleWireshark
3Debian Linux
SolarisWireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds wri...Show more
epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.Show less
1Oracle
1Solaris
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via vectors related to ZFS.
1Oracle
1Solaris
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Network Configuration Service.