Solaris
Vendor:
First CVE: Oct 1, 1993 · Active for 32 years
545
Total CVEs
More Total CVEs than 100% of tracked products
30.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Solaris over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 1993
32 years ago
Most Recent CVE
Nov 11, 2011
5,369 days ago
CVE Severity & Scoring
Solaris545 CVEs
12%
38%
49%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (0.6%)
Network3 (0.6%)
Unknown539 (98.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (0.9%)
High1 (0.2%)
Unknown539 (98.9%)
User Interaction
None6 (1.1%)
Unknown539 (98.9%)
Required0 (0.0%)
Privileges Required
Low2 (0.4%)
High0 (0.0%)
None4 (0.7%)
Unknown539 (98.9%)
Top CVEs
Signals from CVEs in this product scope (545 CVEs).
545 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0201HIGH Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to | May 5, 2003 | 10.0 | 88 | NO | YES |
CVE-2001-0797HIGH Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as | Dec 12, 2001 | 10.0 | 88 | NO | YES |
CVE-2009-3867HIGH Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3. | Nov 5, 2009 | 9.3 | 86 | NO | YES |
CVE-2003-0722HIGH The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privi | Sep 22, 2003 | 10.0 | 85 | NO | YES |
CVE-2003-0466CRITICAL Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug | Aug 27, 2003 | 9.8 | 81 | NO | YES |
CVE-2009-3869HIGH Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JD | Nov 5, 2009 | 9.3 | 80 | NO | YES |
CVE-2008-4556HIGH Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted | Oct 14, 2008 | 10.0 | 80 | NO | YES |
CVE-2001-0236HIGH Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event. | May 3, 2001 | 10.0 | 78 | NO | YES |
CVE-2008-0960HIGH SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC | Jun 10, 2008 | 10.0 | 77 | NO | YES |
CVE-2001-0779HIGH Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username. | Oct 18, 2001 | 10.0 | 75 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (545 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
14 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
118 CVEs
21.7% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (545 CVEs).
Media Mentions
Signals from CVEs in this product scope (545 CVEs).
Top CNAs Publishing CVEs For Solaris
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 139 | 5.8 | 6.5% | 0 | 21 |
| 9 | 35 | 5.7 | 3.5% | 0 | 4 |
| 8.0 | 130 | 6.2 | 6.3% | 0 | 31 |
| 8 | 30 | 5.9 | 3.9% | 0 | 4 |
| 7.0 | 104 | 6.5 | 6.9% | 0 | 46 |
| 5.8 | 1 | 4.6 | 0.5% | 0 | 0 |
| 5.6 | 1 | 7.2 | 1.4% | 0 | 1 |
| 5.5.1 | 1 | 7.2 | 1.4% | 0 | 1 |
| 5.5 | 1 | 7.2 | 1.4% | 0 | 1 |
| 5.4 | 1 | 7.2 | 1.4% | 0 | 1 |
| 4.1.3 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.6 | 128 | 6.8 | 8.2% | 0 | 54 |
| 2.5.1 | 74 | 6.8 | 9.6% | 0 | 39 |
| 2.5 | 56 | 7.0 | 6.1% | 0 | 32 |
| 2.4 | 48 | 7.2 | 6.0% | 0 | 26 |
| 1.1.4 | 4 | 6.5 | 0.8% | 0 | 3 |
| 1.1.3 | 4 | 6.5 | 0.8% | 0 | 3 |
| 10.0 | 118 | 5.6 | 3.0% | 0 | 15 |
| 10 | 78 | 5.5 | 1.3% | 0 | 6 |