Opensolaris

Vendor:

First CVE: Oct 11, 2007 · Active for 18 years

115
Total CVEs
More Total CVEs than 99% of tracked products
19.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Opensolaris over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 11, 2007
18 years ago
Most Recent CVE
Apr 6, 2016
3,761 days ago

CVE Severity & Scoring

Opensolaris115 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (13.9%)
Unknown99 (86.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (13.0%)
High1 (0.9%)
Unknown99 (86.1%)
User Interaction
None12 (10.4%)
Unknown99 (86.1%)
Required4 (3.5%)
Privileges Required
Low2 (1.7%)
High0 (0.0%)
None14 (12.2%)
Unknown99 (86.1%)

Top CVEs

Signals from CVEs in this product scope (115 CVEs).

115 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote a
Oct 11, 20077.271NOYES
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary
Aug 8, 20089.339NOYES
in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon
Nov 10, 200810.036NOYES
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related
Jan 27, 20097.833NOYES
tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCG
Dec 19, 20087.232NOYES
SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP
Jan 27, 20169.830NONO
Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via
Oct 13, 20097.229NOYES
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows
Mar 3, 20169.827NONO
The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access share
Jul 2, 200910.027NONO
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized
Apr 6, 20169.826NONO

Exploit Exposure

Signals from CVEs in this product scope (115 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
7.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (115 CVEs).

Media Mentions

Signals from CVEs in this product scope (115 CVEs).

Top CNAs Publishing CVEs For Opensolaris

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
snv_99475.73.1%05
snv_98475.73.1%05
snv_97465.73.1%05
snv_96475.73.1%05
snv_95465.52.9%05
snv_94505.82.9%05
snv_93515.72.9%05
snv_92535.82.8%05
snv_91565.72.7%05
snv_90555.62.7%05
snv_89555.62.7%05
snv_88555.62.7%05
snv_87545.72.8%05
snv_86565.72.7%05
snv_85595.72.6%05
snv_84575.72.7%05
snv_83575.82.7%05
snv_82605.82.6%05
snv_81605.82.6%05
snv_80615.82.6%05