Solaris

Vendor:

First CVE: Oct 1, 1993 · Active for 32 years

545
Total CVEs
More Total CVEs than 100% of tracked products
30.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Solaris over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 1993
32 years ago
Most Recent CVE
Nov 11, 2011
5,369 days ago

CVE Severity & Scoring

Solaris545 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local3 (0.6%)
Network3 (0.6%)
Unknown539 (98.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (0.9%)
High1 (0.2%)
Unknown539 (98.9%)
User Interaction
None6 (1.1%)
Unknown539 (98.9%)
Required0 (0.0%)
Privileges Required
Low2 (0.4%)
High0 (0.0%)
None4 (0.7%)
Unknown539 (98.9%)

Top CVEs

Signals from CVEs in this product scope (545 CVEs).

545 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to
May 5, 200310.088NOYES
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as
Dec 12, 200110.088NOYES
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.
Nov 5, 20099.386NOYES
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privi
Sep 22, 200310.085NOYES
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug
Aug 27, 20039.881NOYES
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JD
Nov 5, 20099.380NOYES
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted
Oct 14, 200810.080NOYES
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
May 3, 200110.078NOYES
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC
Jun 10, 200810.077NOYES
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
Oct 18, 200110.075NOYES

Exploit Exposure

Signals from CVEs in this product scope (545 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
14 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
118 CVEs
21.7% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (545 CVEs).

Media Mentions

Signals from CVEs in this product scope (545 CVEs).

Top CNAs Publishing CVEs For Solaris

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.01395.86.5%021
9355.73.5%04
8.01306.26.3%031
8305.93.9%04
7.01046.56.9%046
5.814.60.5%00
5.617.21.4%01
5.5.117.21.4%01
5.517.21.4%01
5.417.21.4%01
4.1.317.80.5%00
2.61286.88.2%054
2.5.1746.89.6%039
2.5567.06.1%032
2.4487.26.0%026
1.1.446.50.8%03
1.1.346.50.8%03
10.01185.63.0%015
10785.51.3%06