VendorsOraclesolarisany version
Vulnerabilities

Oracle Solaris any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

206CVEs
CVE-2023-27859
IBM Db2 code execution
Published 2024-01-22 · Modified
6.5EPSS 0.010
CVE-2021-20483
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to obtain sensitive data. IBM X-Force ID: 197591.
Published 2021-06-16 · Modified
6.5EPSS 0.009
CVE-2023-29256
IBM Db2 information disclosure
Published 2023-07-09 · Modified
6.5EPSS 0.008
CVE-2018-21033
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager and Hitachi Compute Systems Manager.
Published 2020-02-14 · Modified
6.5EPSS 0.008
CVE-2020-4259
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638.
Published 2020-05-14 · Modified
6.5EPSS 0.008
CVE-2022-31772
IBM MQ denial of service
Published 2022-11-11 · Modified
6.5EPSS 0.008
CVE-2023-47158
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47746
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2023-47747
IBM Db2 denial of service
Published 2024-01-22 · Modified
6.5EPSS 0.007
CVE-2020-4320
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.
Published 2020-06-16 · Modified
6.5EPSS 0.007
CVE-2024-27254
IBM Db2 for Linux, UNIX and Windows denial of service
Published 2024-04-03 · Analyzed
6.5EPSS 0.007
CVE-2021-39087
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticated user to obtain sensitive information due to improper permission controls. IBM X-Force ID: 216109.
Published 2022-08-16 · Modified
6.5EPSS 0.006
CVE-2019-4738
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive information to an authenticated user from the dashboard UI which could be used in further attacks against the system. IBM X-Force ID: 172753.
Published 2020-12-10 · Modified
6.5EPSS 0.005
CVE-2021-29683
IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 199998.
Published 2021-05-20 · Modified
6.5EPSS 0.005
CVE-2023-30443
IBM Db2 denial of service
Published 2024-12-19 · Analyzed
6.5EPSS 0.005
CVE-2023-29260
IBM Sterling Connect:Express for UNIX server-side request forgery
Published 2023-07-19 · Modified
6.5EPSS 0.003
CVE-2017-0310
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.
Published 2017-02-15 · Modified
6.5EPSS 0.003
CVE-2011-2145
mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and VMware ESX 3.0.3 through 4.1, when a Solaris or FreeBSD guest OS is used, allows guest OS users to modify arbitrary guest OS files via unspecified vectors, related to a "procedural error."
Published 2011-06-06 · Modified
6.3EPSS 0.003
CVE-2021-39048
IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 214438.
Published 2021-12-13 · Modified
6.2EPSS 0.003
CVE-2023-28514
IBM MQ information disclosure
Published 2023-05-19 · Modified
6.2EPSS 0.002
CVE-2021-38949
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Published 2021-11-16 · Modified
6.2EPSS 0.002
CVE-2022-22478
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
Published 2022-06-30 · Modified
6.2EPSS 0.002
CVE-2012-0767
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.
Published 2012-02-16 · Analyzed
6.1KEVEPSS 0.064
CVE-2018-1853
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 151014.
Published 2019-04-08 · Modified
6.1EPSS 0.012
CVE-2022-25256
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL.
Published 2022-02-19 · Modified
6.1EPSS 0.012
CVE-2016-8961
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Published 2017-02-01 · Modified
6.1EPSS 0.009
CVE-2019-4681
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171734.
Published 2020-03-24 · Modified
6.1EPSS 0.007
CVE-2020-4657
IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2020-4658
IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.
Published 2020-12-16 · Modified
6.1EPSS 0.007
CVE-2015-9281
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
Published 2019-01-17 · Modified
6.1EPSS 0.006
CVE-2022-22477
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.
Published 2022-07-14 · Modified
6.1EPSS 0.006
CVE-2019-4568
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629.
Published 2020-01-28 · Modified
5.9EPSS 0.013
CVE-2016-8966
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
Published 2017-02-01 · Modified
5.9EPSS 0.012
CVE-2019-4102
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.
Published 2019-07-01 · Modified
5.9EPSS 0.012
CVE-2021-29692
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 200253.
Published 2021-05-20 · Modified
5.9EPSS 0.010
CVE-2022-38712
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduct SOAPAction spoofing to execute unwanted or unauthorized operations. IBM X-Force ID: 234762."
Published 2022-11-03 · Modified
5.9EPSS 0.005
CVE-2022-35646
IBM Security Verify Governance, Identity Manager security bypass
Published 2022-12-22 · Modified
5.9EPSS 0.004
CVE-2024-45072
IBM WebSphere Application Server XML external entity injection
Published 2024-10-16 · Analyzed
5.5EPSS 0.004
CVE-2018-6253
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.
Published 2018-04-02 · Modified
5.5EPSS 0.004
CVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.
Published 2017-02-01 · Modified
5.5EPSS 0.003
← Prev4 / 6Next →