CVE-2004-1394
published 2004-12-31CVE-2004-1394: The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow…
PriorityP411medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.34%
25.8th percentile
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/10755/http://sunsolve.sun.com/search/document.do?assetkey=1-26-57453-1http://www.auscert.org.au/render.html?it=3800http://www.osvdb.org/3764http://www.securityfocus.com/bid/9534http://www.securitytracker.com/id?1008893https://exchange.xforce.ibmcloud.com/vulnerabilities/14988http://secunia.com/advisories/10755/http://sunsolve.sun.com/search/document.do?assetkey=1-26-57453-1http://www.auscert.org.au/render.html?it=3800http://www.osvdb.org/3764http://www.securityfocus.com/bid/9534http://www.securitytracker.com/id?1008893https://exchange.xforce.ibmcloud.com/vulnerabilities/14988
2004-12-31
Published