cbcvebase.

Sun Opensolaris vulnerabilities

108 known vulnerabilities affecting sun/opensolaris.

Total CVEs
108
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH34MEDIUM61LOW6

Vulnerabilities

Page 2 of 6
CVE-2009-1478P4MEDIUMCVSS 4.9PoCvsnv_01vsnv_02+111 more2009-04-29
CVE-2009-1478 [MEDIUM] CVE-2009-1478: Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.
nvd
CVE-2009-0872P4MEDIUMCVSS 6.8≤ snv_110vsnv_01+108 more2009-03-11
CVE-2009-0872 [MEDIUM] CWE-264 CVE-2009-0872: The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AU The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.
nvd
CVE-2009-0873P4MEDIUMCVSS 6.8vsnv_01vsnv_02+88 more2009-03-11
CVE-2009-0873 [MEDIUM] CWE-264 CVE-2009-0873: The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "ov
nvd
CVE-2009-0923P4HIGHCVSS 7.8vsnv_01vsnv_02+108 more2009-03-17
CVE-2009-0923 [HIGH] CVE-2009-0923: Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 t Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.
nvd
CVE-2009-2487P4HIGHCVSS 7.8vsnv_45vsnv_46+64 more2009-07-16
CVE-2009-2487 [HIGH] CWE-399 CVE-2009-2487: Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.
nvd
CVE-2009-2136P4HIGHCVSS 7.8vsnv_01vsnv_02+86 more2009-06-19
CVE-2009-2136 [HIGH] CVE-2009-2136: Unspecified vulnerability in the TCP/IP networking stack in Sun Solaris 10, and OpenSolaris snv_01 t Unspecified vulnerability in the TCP/IP networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_117, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames.
nvd
CVE-2008-2710P4HIGHCVSS 7.2v102008-06-16
CVE-2008-2710 [HIGH] CWE-189 CVE-2008-2710: Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/i Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an o
nvd
CVE-2009-3899P4HIGHCVSS 7.8vsnv_57vsnv_58+36 more2009-11-06
CVE-2009-3899 [HIGH] CWE-399 CVE-2009-3899: Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 th Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 through snv_94, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvd
CVE-2009-2486P4HIGHCVSS 7.8vsnv_01vsnv_02+117 more2009-07-16
CVE-2009-2486 [HIGH] CVE-2009-2486: Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_1 Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.
nvd
CVE-2009-4190P4HIGHCVSS 7.8v2009.062009-12-03
CVE-2009-4190 [HIGH] CVE-2009-4190: Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause a denial of service (panic) via unknown vectors, as demonstrated by the vd_solaris2 module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher
nvd
CVE-2010-0558P4HIGHCVSS 7.5vsnv_77vsnv_78+53 more2010-02-05
CVE-2010-0558 [HIGH] CWE-16 CVE-2010-0558: The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an u The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.
nvd
CVE-2010-0559P4HIGHCVSS 7.5vsnv_91vsnv_92+39 more2010-02-05
CVE-2010-0559 [HIGH] CWE-16 CVE-2010-0559: The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an u The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.
nvd
CVE-2016-1344P4MEDIUMCVSS 5.9vsnv_1242016-03-26
CVE-2016-1344 [MEDIUM] CWE-399 CVE-2016-1344: The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote at The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
nvd
CVE-2008-5133P4MEDIUMCVSS 5.8≤ snv_95vsnv_01+93 more2008-11-18
CVE-2008-5133 [MEDIUM] CVE-2008-5133: ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server wit ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queri
nvd
CVE-2009-2137P4HIGHCVSS 7.8vsnv_54vsnv_55+57 more2009-06-19
CVE-2009-2137 [HIGH] CWE-399 CVE-2009-2137: Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and Op Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-dependent attackers to cause a denial of service (memory consumption) via unspecified vectors related to a large keylen value.
nvd
CVE-2009-3000P4HIGHCVSS 7.1vsnv_41vsnv_42+80 more2009-08-28
CVE-2009-3000 [HIGH] CWE-399 CVE-2009-3000: The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Netwo The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handl
nvd
CVE-2009-3183P4HIGHCVSS 7.2vsnv_01vsnv_02+121 more2009-09-14
CVE-2009-3183 [HIGH] CWE-119 CVE-2009-3183: Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows local users to gain privileges via unspecified vectors.
nvd
CVE-2009-0277P4HIGHCVSS 7.8vsnv_100vsnv_101+1 more2009-01-27
CVE-2009-0277 [HIGH] CVE-2009-0277: Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors.
nvd
CVE-2009-4226P4HIGHCVSS 7.1vsnv_106vsnv_107+17 more2009-12-08
CVE-2009-4226 [HIGH] CWE-362 CVE-2009-4226: Race condition in the IP module in the kernel in Sun OpenSolaris snv_106 through snv_124 allows remo Race condition in the IP module in the kernel in Sun OpenSolaris snv_106 through snv_124 allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors related to the (1) tcp_do_getsockname or (2) tcp_do_getpeername function.
nvd
CVE-2009-0477P4HIGHCVSS 7.2vsnv_85vsnv_86+14 more2009-02-08
CVE-2009-0477 [HIGH] CWE-264 CVE-2009-0477: Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via vectors related to the contract filesystem.
nvd
Sun Opensolaris vulnerabilities | cvebase