cbcvebase.

Sun Opensolaris vulnerabilities

108 known vulnerabilities affecting sun/opensolaris.

Total CVEs
108
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH34MEDIUM61LOW6

Vulnerabilities

Page 3 of 6
CVE-2009-1763P4HIGHCVSS 7.2vsnv_105vsnv_106+2 more2009-05-22
CVE-2009-1763 [HIGH] CVE-2009-1763: Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_108 on the x86 platform allows local users to gain privileges or cause a denial of service (filesystem or memory corruption) via unknown vectors.
nvd
CVE-2016-1310P4MEDIUMCVSS 6.1vsnv_1242016-02-06
CVE-2016-1310 [MEDIUM] CWE-79 CVE-2016-1310: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attacke Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.
nvd
CVE-2009-3164P4HIGHCVSS 7.1vsnv_01vsnv_02+92 more2009-09-10
CVE-2009-3164 [HIGH] CVE-2009-3164: Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 thr Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix fo
nvd
CVE-2009-4191P4HIGHCVSS 7.2v2009.062009-12-03
CVE-2009-4191 [HIGH] CVE-2009-4191: Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 plat Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated by the vd_sol_local module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a re
nvd
CVE-2016-1331P4MEDIUMCVSS 6.1vsnv_1242016-02-15
CVE-2016-1331 [MEDIUM] CWE-79 CVE-2016-1331: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) all Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.
nvd
CVE-2016-1319P4MEDIUMCVSS 5.3vsnv_1242016-02-09
CVE-2016-1319 [MEDIUM] CWE-200 CVE-2016-1319: Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.1290 Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via
nvd
CVE-2008-3838P4HIGHCVSS 7.2≤ snv_87vsnv_01+85 more2008-08-27
CVE-2008-3838 [HIGH] CWE-20 CVE-2008-3838: Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solari Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.
nvd
CVE-2016-1314P4MEDIUMCVSS 6.1vsnv_1242016-03-28
CVE-2016-1314 [MEDIUM] CWE-79 CVE-2016-1314: Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux80760.
nvd
CVE-2016-1306P4MEDIUMCVSS 6.1vsnv_1242016-02-06
CVE-2016-1306 [MEDIUM] CWE-79 CVE-2016-1306: Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attack Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466.
nvd
CVE-2008-3666P4HIGHCVSS 7.1≤ snv_95vsnv_01+93 more2008-08-13
CVE-2008-3666 [HIGH] CVE-2008-3666: Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-depende Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a
nvd
CVE-2009-2297P4HIGHCVSS 7.1vsnv_90vsnv_91+17 more2009-07-02
CVE-2009-2297 [HIGH] CVE-2009-2297: Unspecified vulnerability in the udp subsystem in the kernel in Sun Solaris 10, and OpenSolaris snv_ Unspecified vulnerability in the udp subsystem in the kernel in Sun Solaris 10, and OpenSolaris snv_90 through snv_108, when Solaris Trusted Extensions is enabled, allows remote attackers to cause a denial of service (panic) via unspecified vectors involving the crgetlabel function, related to a "TX panic." NOTE: this issue exists because of a regression in ear
nvd
CVE-2009-2652P4MEDIUMCVSS 6.8vsnv_37vsnv_38+82 more2009-08-03
CVE-2009-2652 [MEDIUM] CVE-2009-2652: Unspecified vulnerability in Solaris Trusted Extensions in Sun Solaris 10, and OpenSolaris snv_37 th Unspecified vulnerability in Solaris Trusted Extensions in Sun Solaris 10, and OpenSolaris snv_37 through snv_120, allows remote attackers to cause a denial of service (panic) via vectors involving the parsing of labeled packets.
nvd
CVE-2009-3390P4HIGHCVSS 7.2vsnv_30vsnv_31+80 more2009-09-24
CVE-2009-3390 [HIGH] CVE-2009-3390: Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 1 Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris snv_28 through snv_109, allow local users with certain RBAC execution profiles to gain privileges via unknown vectors related to the libima library.
nvd
CVE-2009-1170P4MEDIUMCVSS 6.9vsnv_100vsnv_1012009-03-30
CVE-2009-1170 [MEDIUM] CVE-2009-1170: Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privil Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global zone, to execute arbitrary code in the global zone when a global-zone user is using mdb on a non-global zone process.
nvd
CVE-2009-4075P4MEDIUMCVSS 5.0vsnv_99vsnv_100+23 more2009-11-25
CVE-2009-4075 [MEDIUM] CVE-2009-4075: Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors that trigger a "dangling sshd authentication thread."
nvd
CVE-2008-3875P4HIGHCVSS 7.2≤ build_snv_89vbuild_snv_01+11 more2008-09-02
CVE-2008-3875 [HIGH] CWE-264 CVE-2008-3875: The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass ch The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.
nvd
CVE-2008-6024P4MEDIUMCVSS 5.4≤ snv_36vsnv_01+34 more2009-02-02
CVE-2008-6024 [MEDIUM] CWE-399 CVE-2008-6024: Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris before snv_37, when automountd is used, allows user-assisted remote attackers to cause a denial of service (unresponsive NFS filesystems) via unknown vectors.
nvd
CVE-2009-0875P4MEDIUMCVSS 6.9≤ snv_93vsnv_01+91 more2009-03-12
CVE-2009-0875 [MEDIUM] CWE-362 CVE-2009-0875: Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris bef Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
nvd
CVE-2009-0267P4MEDIUMCVSS 5.0≤ snv_99vsnv_01+97 more2009-01-26
CVE-2009-0267 [MEDIUM] CVE-2009-0267: libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, whi libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
nvd
CVE-2009-0319P4MEDIUMCVSS 6.9≤ snv_107vsnv_01+105 more2009-01-28
CVE-2009-0319 [MEDIUM] CVE-2009-0319: Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSo Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."
nvd
Sun Opensolaris vulnerabilities | cvebase