navigation bar left navigation bar right

navigation left tab Advisories navigation right tab
navigation left tab Research navigation right tab
navigation left tab Forums navigation right tab
navigation left tab Create Profile navigation right tab
navigation left tab Our Commitment navigation right tab
Database
Search
Advisories by Product
Advisories by Vendor
Terminology
Report Vulnerability
Insecure Library Loading

Vulnerability Report: Sun Solaris 10.x

This vulnerability report for Sun Solaris 10.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Sun Solaris 10.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2014
2.2. Statistics for 2013
2.3. Statistics for 2012
2.4. Statistics for 2011
2.5. Statistics for 2010
2.6. Statistics for 2009
2.7. Statistics for 2008
2.8. Statistics for 2007
2.9. Statistics for 2006
2.10. Statistics for 2005
2.11. Statistics for 2004
2.12. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2014
3.2. List for 2013
3.3. List for 2012
3.4. List for 2011
3.5. List for 2010
3.6. List for 2009
3.7. List for 2008
3.8. List for 2007
3.9. List for 2006
3.10. List for 2005
3.11. List for 2004
3.12. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Sun Microsystems

Product Link View Here (Link to external site)

Affected By 561 Secunia advisories
1816 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 1% (7 of 561 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Sun Solaris 10.x, with all vendor patches applied, is rated Highly critical .




37 Secunia Advisories in 2013

Secunia has issued a total of 37 Secunia advisories in 2013 for Sun Solaris 10.x. Currently, 0% (0 out of 37) are marked as unpatched.

More information about the specific Secunia advisories affecting Sun Solaris 10.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



patched Oracle Solaris Perl Digest "Digest->new()" Code Injection Vulnerability
Vendor Patch. Secunia Advisory 1 of 37 in 2013. 3,093 views.
Release Date:
2013-10-31
Secunia Advisory ID:
SA55382
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Perl included in Solaris, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


partial Oracle Solaris Perl "File::Glob::bsd_glob()" Vulnerability
Partial Fix. Secunia Advisory 2 of 37 in 2013. 3,278 views.
Release Date:
2013-10-31
Secunia Advisory ID:
SA55379
Solution Status:
Partial Fix
Criticality:
Moderately critical
Impact:
Privilege escalation
DoS
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Perl included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system. [Read More]


patched Oracle Solaris Mozilla Firefox Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 37 in 2013. 3,691 views.
Release Date:
2013-10-16
Secunia Advisory ID:
SA55318
Solution Status:
Vendor Patch
Criticality:
Highly critical
Impact:
Cross Site Scripting
System access
Security Bypass
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Firefox included in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system. [Read More]


patched Oracle Solaris Perl Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 37 in 2013. 1,362 views.
Release Date:
2013-10-16
Secunia Advisory ID:
SA55314
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
Privilege escalation
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Perl included in Solaris, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to potentially compromise a vulnerable system. [Read More]


patched Oracle Solaris Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 5 of 37 in 2013. 1,088 views.
Release Date:
2013-10-16
Secunia Advisory ID:
SA55326
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
Manipulation of data
Exposure of sensitive information
DoS
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious, local users to disclose certain sensitive information, manipulate certain data, and cause a DoS (Denial of Service) and by malicious people to manipulate certain data and cause a DoS. [Read More]


patched Oracle Solaris Samba Packet Handling Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 6 of 37 in 2013. 987 views.
Release Date:
2013-10-16
Secunia Advisory ID:
SA55320
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
DoS
Where:
From local network
Short Description:
Oracle has acknowledged a vulnerability in Samba included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris Poppler Unspecified Vulnerabilities
Vendor Patch. Secunia Advisory 7 of 37 in 2013. 863 views.
Release Date:
2013-09-25
Secunia Advisory ID:
SA55037
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
Unknown
Where:
From remote
Short Description:
Oracle has acknowledged some vulnerabilities with unknown impacts in Poppler included in Solaris. [Read More]


patched Oracle Solaris LibXSLT "xsltDocumentFunction()" and "xsltAddKey()" Denial of Service Vulnerabilities
Vendor Patch. Secunia Advisory 8 of 37 in 2013. 911 views.
Release Date:
2013-09-25
Secunia Advisory ID:
SA55030
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
DoS
Where:
From remote
Short Description:
Oracle has acknowledged two vulnerabilities in LibXSLT included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


partial Oracle Solaris Apache HTTP Server Multiple Vulnerabilities
Partial Fix. Secunia Advisory 9 of 37 in 2013. 2,215 views.
Release Date:
2013-09-25
Secunia Advisory ID:
SA55032
Solution Status:
Partial Fix
Criticality:
Moderately critical
Impact:
Cross Site Scripting
DoS
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Apache HTTP Server included in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and compromise a vulnerable system. [Read More]


patched Oracle Solaris Tomcat FormAuthenticator Session Hijacking Weakness
Vendor Patch. Secunia Advisory 10 of 37 in 2013. 785 views.
Release Date:
2013-09-25
Secunia Advisory ID:
SA55033
Solution Status:
Vendor Patch
Criticality:
Not critical
Impact:
Hijacking
Where:
From remote
Short Description:
Oracle has acknowledged a weakness in Tomcat included in Solaris, which can be exploited by malicious people to hijack a user's session. [Read More]


partial Oracle Solaris X.org Multiple Vulnerabilities
Partial Fix. Secunia Advisory 11 of 37 in 2013. 942 views.
Release Date:
2013-09-25
Secunia Advisory ID:
SA55041
Solution Status:
Partial Fix
Criticality:
Less critical
Impact:
DoS
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in X.Org included in Solaris, which can be exploited by malicious users to cause a DoS (Denial of Service) and by malicious people to compromise an application using the library. [Read More]


patched Oracle Solaris Kerberos kpasswd UDP Packet Processing Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 12 of 37 in 2013. 871 views.
Release Date:
2013-09-25
Secunia Advisory ID:
SA55039
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
DoS
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Kerberos included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris Apache HTTP Server Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 13 of 37 in 2013. 934 views.
Release Date:
2013-07-17
Secunia Advisory ID:
SA54224
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
Cross Site Scripting
Privilege escalation
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Apache HTTP Server included in Solaris, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to conduct cross-site scripting attacks. [Read More]


patched Oracle Solaris OpenSSH Weakness
Vendor Patch. Secunia Advisory 14 of 37 in 2013. 900 views.
Release Date:
2013-07-17
Secunia Advisory ID:
SA54229
Solution Status:
Vendor Patch
Criticality:
Not critical
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
Oracle has acknowledged a weakness in OpenSSH included in Solaris, which can be exploited by malicious users to disclose potentially sensitive information. [Read More]


patched Oracle Solaris Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 15 of 37 in 2013. 1,239 views.
Release Date:
2013-07-17
Secunia Advisory ID:
SA54235
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
Manipulation of data
Exposure of sensitive information
Privilege escalation
DoS
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and gain escalated privileges and by malicious people to disclose certain sensitive information, manipulate certain data, and cause a DoS (Denial of Service) [Read More]


patched Oracle Solaris Pidgin MXit Message Parsing Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 16 of 37 in 2013. 885 views.
Release Date:
2013-07-17
Secunia Advisory ID:
SA54228
Solution Status:
Vendor Patch
Criticality:
Highly critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Pidgin included in Solaris, which can be exploited by malicious people to compromise a user's system. [Read More]


patched Oracle Solaris X.Org xrdb Hostname Command Injection Security Issue
Vendor Patch. Secunia Advisory 17 of 37 in 2013. 1,256 views.
Release Date:
2013-07-03
Secunia Advisory ID:
SA53782
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
Privilege escalation
System access
Where:
From local network
Short Description:
Oracle has acknowledged a security issue in X.Org xrdb included in Solaris, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to compromise a vulnerable system. [Read More]


patched Oracle Solaris Perl Locale::Maketext Two Code Injection Vulnerabilities
Vendor Patch. Secunia Advisory 18 of 37 in 2013. 1,317 views.
Release Date:
2013-07-03
Secunia Advisory ID:
SA54047
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged two vulnerabilities in Perl included in Solaris, which can be exploited by malicious people to compromise an application using the module. [Read More]


patched Oracle Solaris Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 19 of 37 in 2013. 1,980 views.
Release Date:
2013-05-22
Secunia Advisory ID:
SA53468
Solution Status:
Vendor Patch
Criticality:
Highly critical
Impact:
Exposure of sensitive information
DoS
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in multiple packages included in Solaris, which can be exploited by malicious users to disclose potentially sensitive information and by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise an application using the library. [Read More]


patched Oracle Solaris Perl Input Rehashing Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 20 of 37 in 2013. 1,732 views.
Release Date:
2013-05-08
Secunia Advisory ID:
SA53367
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
DoS
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Perl included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris Apache Ant Bzip2 Compression Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 21 of 37 in 2013. 1,707 views.
Release Date:
2013-05-01
Secunia Advisory ID:
SA53194
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
DoS
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Apache Ant included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris Samba SWAT Clickjacking Vulnerability
Vendor Patch. Secunia Advisory 22 of 37 in 2013. 1,734 views.
Release Date:
2013-05-01
Secunia Advisory ID:
SA53282
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Samba included in Solaris, which can be exploited by malicious people to conduct clickjacking attacks. [Read More]


patched Oracle Solaris Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 23 of 37 in 2013. 1,423 views.
Release Date:
2013-04-17
Secunia Advisory ID:
SA53070
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
Manipulation of data
Exposure of sensitive information
Privilege escalation
DoS
Where:
From remote
Short Description:
Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and gain escalated privileges and by malicious people to disclose potentially sensitive information and manipulate certain data. [Read More]


patched Oracle Solaris C Library "fnmatch()" Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 24 of 37 in 2013. 1,415 views.
Release Date:
2013-04-11
Secunia Advisory ID:
SA52997
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Solaris C Library, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris Python Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 25 of 37 in 2013. 1,561 views.
Release Date:
2013-04-11
Secunia Advisory ID:
SA52942
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
Hijacking
Exposure of sensitive information
DoS
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Python included in Solaris, which can be exploited by malicious people to disclose potentially sensitive information, hijack a user's session, and cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris ISC BIND Bad Cache Assertion Failure Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 26 of 37 in 2013. 1,457 views.
Release Date:
2013-04-11
Secunia Advisory ID:
SA52933
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
DoS
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in ISC BIND included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris PostgreSQL "enum_recv()" Denial of Service Vulnerability
Vendor Patch. Secunia Advisory 27 of 37 in 2013. 1,775 views.
Release Date:
2013-04-03
Secunia Advisory ID:
SA52819
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
DoS
Where:
From local network
Short Description:
Oracle has acknowledged a vulnerability in PostgreSQL included in Solaris, which can be exploited by malicious users to cause a DoS (Denial of Service). [Read More]


patched Oracle Solaris GLib Base64 Multiple Integer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 28 of 37 in 2013. 1,095 views.
Release Date:
2013-03-20
Secunia Advisory ID:
SA52732
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in GLib included in Solaris, which can potentially be exploited by malicious people to compromise an application using the library. [Read More]


patched Oracle Solaris Python Multiple Integer Overflow Vulnerabilities
Vendor Patch. Secunia Advisory 29 of 37 in 2013. 1,050 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52595
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
DoS
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Python included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. [Read More]


patched Oracle Solaris libpng Two Vulnerabilities
Vendor Patch. Secunia Advisory 30 of 37 in 2013. 1,115 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52604
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged two vulnerabilities in libpng included in Solaris, which can be exploited by malicious people to compromise an application using the library. [Read More]


patched Oracle Solaris FreeType 2 Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 31 of 37 in 2013. 1,222 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52618
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in FreeType 2 included in Solaris, which can be exploited by malicious people to compromise an application using the library. [Read More]


patched Oracle Solaris Thunderbird Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 32 of 37 in 2013. 1,232 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52614
Solution Status:
Vendor Patch
Criticality:
Highly critical
Impact:
Security Bypass
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in Thunderbird included in Solaris, which can be exploited by malicious people to bypass certain security restrictions, disclose certain sensitive information, and compromise a user's system. [Read More]


patched Oracle Solaris FreeType Font Parsing Vulnerabilities
Vendor Patch. Secunia Advisory 33 of 37 in 2013. 1,208 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52579
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in FreeType included in Solaris, which can be exploited by malicious people to compromise an application using the library. [Read More]


patched Oracle Solaris libxslt Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 34 of 37 in 2013. 1,080 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52619
Solution Status:
Vendor Patch
Criticality:
Highly critical
Impact:
DoS
System access
Where:
From remote
Short Description:
Oracle has acknowledged multiple vulnerabilities in libxslt included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library. [Read More]


patched Oracle Solaris Gzip Input Sanitation Vulnerability
Vendor Patch. Secunia Advisory 35 of 37 in 2013. 1,092 views.
Release Date:
2013-03-14
Secunia Advisory ID:
SA52583
Solution Status:
Vendor Patch
Criticality:
Moderately critical
Impact:
DoS
System access
Where:
From remote
Short Description:
Oracle has acknowledged a vulnerability in Gzip included in Solaris, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system. [Read More]


patched Oracle Solaris X.Org xrdb Hostname Command Injection Security Issue
Vendor Patch. Secunia Advisory 36 of 37 in 2013. 1,107 views.
Release Date:
2013-03-11
Secunia Advisory ID:
SA52564
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
Privilege escalation
System access
Where:
From local network
Short Description:
Oracle has acknowledged a security issue in X.Org xrdb included in Solaris, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to compromise a vulnerable system. [Read More]


patched Oracle Solaris Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 37 of 37 in 2013. 2,275 views.
Release Date:
2013-01-16
Secunia Advisory ID:
SA51892
Solution Status:
Vendor Patch
Criticality:
Less critical
Impact:
Manipulation of data
Exposure of sensitive information
Privilege escalation
DoS
Where:
Local system
Short Description:
Multiple vulnerabilities have been reported in Oracle Solaris, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and gain escalated privileges. [Read More]





Discuss this Product
A new thread in our forum is automatically created for each Product. Activate the thread by commenting/discussing below.
Subject: Sun Solaris 10.x 
No posts yet

-

You must be logged in to post a comment.



 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


Secunia is a member of FIRST Secunia is a member of EDUcause Secunia is a member of The Open Group Secunia is a member of FS-ISAC
 
Secunia © 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability - Disclaimer
follow Secunia on Facebook follow Secunia on Twitter follow Secunia on LinkedIn follow Secunia on YouTube follow Secunia Xing follow Secunias RSS feed follow Secunia on Google+