U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
There are 118 matching records.
Displaying matches 101 through 118.
Vuln ID Summary CVSS Severity
CVE-2010-3507

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Live Upgrade.

Published: October 13, 2010; 10:00:02 PM -0400
V3.x:(not available)
V2.0: 6.6 MEDIUM
CVE-2010-3503

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrity via unknown vectors related to su.

Published: October 13, 2010; 10:00:02 PM -0400
V3.x:(not available)
V2.0: 6.3 MEDIUM
CVE-2010-2400

Unspecified vulnerability in Oracle Solaris 9 and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to Kernel/Filesystem.

Published: July 13, 2010; 6:30:03 PM -0400
V3.x:(not available)
V2.0: 4.6 MEDIUM
CVE-2010-2399

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability via unknown vectors related to Kernel/VM.

Published: July 13, 2010; 6:30:03 PM -0400
V3.x:(not available)
V2.0: 4.6 MEDIUM
CVE-2010-2394

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to TCP/IP.

Published: July 13, 2010; 6:30:03 PM -0400
V3.x:(not available)
V2.0: 4.7 MEDIUM
CVE-2010-2393

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability, related to RPC.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 3.8 LOW
CVE-2010-2392

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect integrity and availability, related to ZFS.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 5.6 MEDIUM
CVE-2010-2386

Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to GigaSwift Ethernet Driver.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 4.9 MEDIUM
CVE-2010-2384

Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 3.2 LOW
CVE-2010-2383

Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 3.2 LOW
CVE-2010-2382

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 3.2 LOW
CVE-2010-2376

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console.

Published: July 13, 2010; 6:30:02 PM -0400
V3.x:(not available)
V2.0: 3.2 LOW
CVE-2009-3519

Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages.

Published: October 01, 2009; 11:30:00 AM -0400
V3.x:(not available)
V2.0: 4.9 MEDIUM
CVE-2009-2857

The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.

Published: August 19, 2009; 1:30:01 PM -0400
V3.1: 5.5 MEDIUM
V2.0: 4.9 MEDIUM
CVE-2009-2282

The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.

Published: July 01, 2009; 9:00:01 AM -0400
V3.x:(not available)
V2.0: 4.6 MEDIUM
CVE-2008-4609

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.

Published: October 20, 2008; 1:59:26 PM -0400
V3.x:(not available)
V2.0: 7.1 HIGH
CVE-2007-0882

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Published: February 12, 2007; 3:28:00 PM -0500
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2004-0230

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

Published: August 18, 2004; 12:00:00 AM -0400
V3.x:(not available)
V2.0: 5.0 MEDIUM