The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Computer vulnerabilities of Solaris

LibTIFF: NULL pointer dereference via TIFFRewriteDirectory
An attacker can force a NULL pointer to be dereferenced via TIFFRewriteDirectory() of LibTIFF, in order to trigger a denial of service...
2820, bulletinoct2019, CVE-2018-19210, DLA-1680-1, openSUSE-SU-2018:4053-1, openSUSE-SU-2018:4256-1, openSUSE-SU-2019:1161-1, SSA:2019-308-01, SUSE-SU-2018:4008-1, SUSE-SU-2018:4191-1, SUSE-SU-2019:0786-1, USN-3906-1, VIGILANCE-VUL-27764
ImageMagick: out-of-bounds memory reading via EncodeImage
An attacker can force a read at an invalid address via EncodeImage() of ImageMagick, in order to trigger a denial of service, or to obtain sensitive information...
bulletinoct2018, CVE-2018-18025, DLA-1574-1, USN-4034-1, VIGILANCE-VUL-27761
OpenSSL: information disclosure via ECC Scalar Multiplication
On an Intel processor (VIGILANCE-VUL-27667), an attacker can measure the execution time of the ECC Scalar Multiplication of OpenSSL, in order to obtain the used key...
bulletinjan2019, CERTFR-2018-AVI-607, CERTFR-2019-AVI-242, cpuapr2019, cpujan2019, cpujan2020, cpujul2019, CVE-2018-5407, DLA-1586-1, DSA-2019-197, DSA-2020-030, DSA-4348-1, DSA-4355-1, ibm10794537, ibm10875298, ibm10886313, K49711130, openSUSE-SU-2018:3903-1, openSUSE-SU-2018:4050-1, openSUSE-SU-2018:4104-1, openSUSE-SU-2019:0088-1, openSUSE-SU-2019:0234-1, RHSA-2019:0483-01, RHSA-2019:2125-01, SSA:2018-325-01, SUSE-SU-2018:3864-1, SUSE-SU-2018:3864-2, SUSE-SU-2018:3866-1, SUSE-SU-2018:3964-1, SUSE-SU-2018:3989-1, SUSE-SU-2018:4001-1, SUSE-SU-2018:4068-1, SUSE-SU-2018:4274-1, SUSE-SU-2019:0117-1, SUSE-SU-2019:0395-1, SUSE-SU-2019:1553-1, SYMSA1490, TNS-2018-16, TNS-2018-17, USN-3840-1, VIGILANCE-VUL-27760
AccountsService: directory traversal via user_change_icon_file_authorized_cb
An attacker can traverse directories via user_change_icon_file_authorized_cb() of AccountsService, in order to read a file outside the service root path...
bulletinoct2018, CVE-2018-14036, openSUSE-SU-2018:3710-1, SUSE-SU-2018:3625-1, VIGILANCE-VUL-27699
Intel processors: information disclosure via SMT/Hyper-Threading PortSmash
An attacker can bypass access restrictions to data via SMT/Hyper-Threading PortSmash on an Intel processor, in order to obtain sensitive information...
530514, bulletinjan2019, CERTFR-2019-AVI-242, cpuapr2019, cpujan2019, cpujan2020, cpujul2019, CVE-2018-5407, DSA-2018-030, DSA-2019-197, DSA-2020-030, DSA-4348-1, DSA-4355-1, ibm10794537, K49711130, openSUSE-SU-2018:4050-1, openSUSE-SU-2018:4104-1, openSUSE-SU-2019:0088-1, openSUSE-SU-2019:0234-1, RHSA-2019:2125-01, SUSE-SU-2018:3964-1, SUSE-SU-2018:3989-1, SUSE-SU-2018:4001-1, SUSE-SU-2018:4068-1, SUSE-SU-2018:4274-1, SUSE-SU-2019:0117-1, SUSE-SU-2019:0395-1, SUSE-SU-2019:1553-1, USN-3840-1, VIGILANCE-VUL-27667
Apache Tomcat JK mod_jk: information disclosure via Reverse Proxy
An attacker can bypass access restrictions to data via Reverse Proxy of Apache Tomcat JK mod_jk, in order to obtain sensitive information...
bulletinjan2019, CVE-2018-11759, DLA-1609-1, DSA-4357-1, openSUSE-SU-2018:4032-1, SUSE-SU-2018:3963-1, SUSE-SU-2018:3963-2, SUSE-SU-2018:3969-1, SUSE-SU-2018:3970-1, VIGILANCE-VUL-27665
libcurl: out-of-bounds memory reading via Warning Message
An attacker can force a read at an invalid address via Warning Message of libcurl, in order to trigger a denial of service, or to obtain sensitive information...
bulletinoct2018, CVE-2018-16842, DLA-1568-1, DSA-2019-114, DSA-2020-030, DSA-4331-1, FEDORA-2018-298a3d2923, FEDORA-2018-69bac0f51c, FEDORA-2018-7785911c9e, FEDORA-2018-fdc4ca8675, openSUSE-SU-2018:3699-1, openSUSE-SU-2018:3706-1, RHSA-2019:2181-01, SSA:2018-304-01, STORM-2019-002, SUSE-SU-2018:3624-1, SUSE-SU-2018:3681-1, SUSE-SU-2019:0339-1, USN-3805-1, USN-3805-2, VIGILANCE-VUL-27650
libcurl: use after free via Curl_close
An attacker can force the usage of a freed memory area via Curl_close() of libcurl, in order to trigger a denial of service, and possibly to run code...
bulletinoct2018, CVE-2018-16840, DSA-2019-114, DSA-2020-030, FEDORA-2018-298a3d2923, FEDORA-2018-69bac0f51c, FEDORA-2018-7785911c9e, FEDORA-2018-fdc4ca8675, openSUSE-SU-2018:3699-1, openSUSE-SU-2018:3706-1, SSA:2018-304-01, SUSE-SU-2018:3624-1, SUSE-SU-2018:3681-1, SUSE-SU-2019:0339-1, USN-3805-1, VIGILANCE-VUL-27649
libcurl: buffer overflow via Curl_auth_create_plain_message
An attacker can generate a buffer overflow via Curl_auth_create_plain_message() of libcurl, in order to trigger a denial of service, and possibly to run code...
bulletinoct2018, CVE-2018-16839, DLA-1568-1, DSA-4331-1, FEDORA-2018-298a3d2923, FEDORA-2018-69bac0f51c, FEDORA-2018-7785911c9e, FEDORA-2018-fdc4ca8675, openSUSE-SU-2018:3706-1, SSA:2018-304-01, STORM-2019-002, SUSE-SU-2018:3624-1, SUSE-SU-2019:0339-1, SUSE-SU-2019:0996-1, USN-3805-1, VIGILANCE-VUL-27648
libarchive: out-of-bounds memory reading via archive_read_format_rar_read_header
An attacker can force a read at an invalid address via archive_read_format_rar_read_header() of libarchive, in order to trigger a denial of service, or to obtain sensitive information...
bulletinjan2019, CVE-2017-14502, DLA-1600-1, DSA-4360-1, FEDORA-2018-20c24949c0, FEDORA-2018-7734354526, openSUSE-SU-2018:3690-1, openSUSE-SU-2018:3717-1, SUSE-SU-2018:3571-1, SUSE-SU-2018:3640-1, SUSE-SU-2018:3640-2, SUSE-SU-2019:3092-1, USN-3859-1, VIGILANCE-VUL-27647
Our database contains other pages. You can request a free trial to read them.

Display information about Solaris: