Omniosce maintains OmniOS, a specialized illumos-derived operating system for enterprise storage and infrastructure, where disclosed vulnerabilities center on memory-safety and authorization issues such as classic buffer overflows, improper input validation, improper locking, and missing authorization controls. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omniosce over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27678CRITICAL An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_u | Oct 26, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-24718HIGH bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write op | Sep 25, 2020 | 8.2 | 25 | NO | NO |
CVE-2019-19396HIGH illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, beca | Nov 29, 2019 | 7.5 | 23 | NO | NO |
CVE-2021-43395MEDIUM An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unp | Dec 26, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omniosce.
Media articles that mention a CVE ID that affects a product developed by Omniosce — matched by CVE ID, not by vendor name.