← Back

Solaris

solaris

Vendor: Oracle • 555 CVEs

CVEs (555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Debian
MariadbOpensuse Project+3 more
12Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+9 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors relat...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.Show less
3Mariadb
OracleSuse
6Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
2.8 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED.
4Mozilla
OpensuseOpensuse Project+1 more
4Firefox
OpensuseOpensuse+1 more
May 6, 2026
Jun 11, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rat...Show more
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.Show less
3Gnome
OpensuseOracle
3Gnome Terminal
OpensuseSolaris
May 6, 2026
May 21, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demons...Show more
The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing the string "\033[100000000000000000@".Show less
6Canonical
FedoraprojectMozilla+3 more
7Fedora
FirefoxOpensuse+4 more
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds w...Show more
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.Show less
3Fedoraproject
MozillaOracle
3Fedora
FirefoxSolaris
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it o...Show more
Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.Show less
3Mariadb
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
3Mariadb
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR.
3Mariadb
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
2.8 LOW· v2
Unspecified vulnerability Oracle the MySQL Server component 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Federated.
3Mariadb
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect availability via unknown vectors related to Options.
3Mariadb
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema.
3Mariadb
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.
5Apache
AppleCanonical+2 more
15Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+12 more
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the...Show more
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."Show less
6Canonical
DebianOracle+3 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
May 6, 2026
Mar 21, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in...Show more
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.Show less
2Mozilla
Oracle
2Firefoxos
Solaris
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted applicatio...Show more
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.Show less
2Mozilla
Oracle
2Firefox
Solaris
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (applic...Show more
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.Show less
4Mozilla
OpensuseOracle+1 more
7Firefox
Linux Enterprise DesktopLinux Enterprise Sdk+4 more
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
2.6 LOW· v2
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scriptin...Show more
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.Show less
5Mozilla
OpensuseOpensuse Project+2 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a...Show more
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.Show less
3Mozilla
OracleSuse
5Firefox
Linux Enterprise DesktopLinux Enterprise Server+2 more
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
5Mozilla
OpensuseOpensuse Project+2 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution...Show more
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.Show less