Solaris
Vendor:
First CVE: Feb 6, 1997 · Active for 29 years
556
Total CVEs
More Total CVEs than 100% of tracked products
23.2
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 20% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Solaris over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 1997
29 years ago
Most Recent CVE
Jul 21, 2026
7 days ago
CVE Severity & Scoring
Solaris556 CVEs
19%
52%
27%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local142 (25.5%)
Network102 (18.3%)
Unknown311 (55.9%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low185 (33.3%)
High60 (10.8%)
Unknown311 (55.9%)
User Interaction
None176 (31.7%)
Unknown311 (55.9%)
Required69 (12.4%)
Privileges Required
Low119 (21.4%)
High28 (5.0%)
None98 (17.6%)
Unknown311 (55.9%)
Top CVEs
Signals from CVEs in this product scope (556 CVEs).
556 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2992HIGH Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript fun | Nov 4, 2008 | 7.8 | 98 | YES | YES |
CVE-2020-14871CRITICAL Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable v | Oct 21, 2020 | 10.0 | 97 | YES | YES |
CVE-2015-4495HIGH The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr | Aug 8, 2015 | 8.8 | 96 | YES | YES |
CVE-2016-3718MEDIUM The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted ima | May 5, 2016 | 5.5 | 93 | YES | YES |
CVE-2016-3715MEDIUM The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | May 5, 2016 | 5.5 | 93 | YES | YES |
CVE-2007-0882HIGH Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the | Feb 12, 2007 | 10.0 | 91 | NO | YES |
CVE-2016-2776HIGH buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause | Sep 28, 2016 | 7.5 | 87 | NO | YES |
CVE-2019-3010HIGH Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low p | Oct 16, 2019 | 8.8 | 86 | YES | YES |
CVE-2017-5753MEDIUM Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side | Jan 4, 2018 | 5.6 | 83 | NO | YES |
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (556 CVEs).
CISA KEV
6 CVEs
1.1% of CVEs· 97th percentile
Metasploit
10 CVEs
1.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
5.2% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (556 CVEs).
Media Mentions
Signals from CVEs in this product scope (556 CVEs).
Top CNAs Publishing CVEs For Solaris
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 20 | 5.2 | 9.8% | 1 | 5 |
| 8 | 17 | 5.8 | 11.0% | 0 | 4 |
| 7.0 | 2 | 10.0 | 62.0% | 0 | 2 |
| 2.6 | 2 | 10.0 | 62.0% | 0 | 2 |
| 2.5.1 | 1 | 10.0 | 51.9% | 0 | 1 |
| 11_express | 5 | 3.8 | 1.2% | 0 | 0 |
| 11.4 | 11 | 7.0 | 0.5% | 0 | 0 |
| 11.3 | 286 | 5.9 | 6.6% | 3 | 9 |
| 11.2 | 79 | 5.2 | 6.0% | 0 | 1 |
| 11.1 | 1 | 10.0 | 2.2% | 0 | 0 |
| 11 | 120 | 5.5 | 3.1% | 1 | 8 |
| 10.0 | 27 | 6.5 | 7.0% | 0 | 2 |
| 10 | 121 | 5.6 | 9.0% | 3 | 16 |