← Back

Solaris

solaris

Vendor: Oracle • 555 CVEs

CVEs (555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
2Opensolaris
Solaris
Apr 29, 2026
Jul 13, 2010
N/A· v4
N/A· v3
3.2 LOW· v2
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS.
1Oracle
1Solaris
Apr 29, 2026
Jul 13, 2010
N/A· v4
N/A· v3
3.2 LOW· v2
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors.
1Oracle
1Solaris
Apr 29, 2026
Jul 13, 2010
N/A· v4
N/A· v3
3.2 LOW· v2
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console.
1Oracle
2Opensolaris
Solaris
Apr 23, 2026
Oct 1, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2)...Show more
Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages.Show less
1Oracle
2Opensolaris
Solaris
Apr 23, 2026
Aug 19, 2009
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of servic...Show more
The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.Show less
1Oracle
2Opensolaris
Solaris
Apr 23, 2026
Jul 1, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, whic...Show more
The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.Show less
2Adobe
Oracle
3Acrobat
Acrobat ReaderSolaris
Apr 22, 2026
Nov 4, 2008
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argum...Show more
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.Show less
12Bsd
BsdiCisco+9 more
19Bsd
Bsd OsCatalyst Blade Switch 3020 Firmware+16 more
Apr 23, 2026
Oct 20, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue...Show more
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.Show less
2Oracle
Sun
2Solaris
Sunos
Apr 23, 2026
Feb 12, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, wh...Show more
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.Show less
2Gnu
Oracle
2Gzip
Solaris
Apr 16, 2026
Oct 4, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
7Juniper
McafeeMicrosoft+4 more
12Junos
NetbsdNetwork Data Loss Prevention+9 more
May 2, 2025
Aug 18, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet,...Show more
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.Show less
7Gentoo
HpNetbsd+4 more
9Alphaserver Sc
BsdosHp Ux+6 more
Apr 16, 2026
Mar 7, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of...Show more
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.Show less
3Hp
OracleSgi
3Hp Ux
IrixSolaris
Apr 16, 2026
Jun 18, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
11Apple
CiscoHp+8 more
14Aix
BsdosHp Ux+11 more
May 28, 2026
Aug 1, 1997
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
10Bsdi
DebianDigital+7 more
10Aix
Bsd OsDebian Linux+7 more
Apr 16, 2026
Feb 6, 1997
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow of rlogin program using TERM environmental variable.