Sun Opensolaris vulnerabilities
108 known vulnerabilities affecting sun/opensolaris.
Total CVEs
108
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH34MEDIUM61LOW6
Vulnerabilities
Page 4 of 6
CVE-2008-5661P4MEDIUMCVSS 5.4vsnv_47vsnv_48+34 more2008-12-17
CVE-2008-5661 [MEDIUM] CWE-399 CVE-2008-5661: The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain pa
The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.
nvd
CVE-2008-5684P4MEDIUMCVSS 5.0≤ snv_84vsnv_01+83 more2008-12-19
CVE-2008-5684 [MEDIUM] CWE-399 CVE-2008-5684: Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 throu
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
nvd
CVE-2009-2029P4MEDIUMCVSS 5.0≤ snv_103vsnv_01+101 more2009-06-11
CVE-2009-2029 [MEDIUM] CVE-2009-2029: Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, a
Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.
nvd
CVE-2008-5699P4MEDIUMCVSS 4.6vsnv_50vsnv_51+53 more2008-12-22
CVE-2008-5699 [MEDIUM] CWE-264 CVE-2008-5699: The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv_50 through snv_104 does n
The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv_50 through snv_104 does not properly check permissions, which allows local users to gain privileges and obtain sensitive information via unspecified vectors.
nvd
CVE-2009-1207P4MEDIUMCVSS 4.4vsnv_01vsnv_02+109 more2009-04-01
CVE-2009-1207 [MEDIUM] CWE-362 CVE-2009-1207: Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_
Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.
nvd
CVE-2009-3101P4MEDIUMCVSS 4.9vsnv_109vsnv_110+21 more2009-09-08
CVE-2009-3101 [MEDIUM] CWE-399 CVE-2009-3101: xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 10, and OpenSolaris snv_109 through snv_122, do
xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 10, and OpenSolaris snv_109 through snv_122, does not properly handle Trusted Extensions, which allows local users to cause a denial of service (CPU consumption and console hang) by locking the screen, related to a regression in certain Solaris and OpenSolaris patches.
nvd
CVE-2009-0874P4MEDIUMCVSS 4.9≤ snv_93vsnv_01+91 more2009-03-12
CVE-2009-0874 [MEDIUM] CWE-399 CVE-2009-0874: Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 1
Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door ser
nvd
CVE-2009-0346P4MEDIUMCVSS 4.9vsnv_01vsnv_02+91 more2009-01-29
CVE-2009-0346 [MEDIUM] CWE-310 CVE-2009-0346: The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solari
The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
nvd
CVE-2009-1933P4MEDIUMCVSS 4.7≤ snv_107≤ snv_116+115 more2009-06-05
CVE-2009-1933 [MEDIUM] CWE-255 CVE-2009-1933: Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage crede
Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.
nvd
CVE-2009-2430P4MEDIUMCVSS 4.6vsnv_01vsnv_02+56 more2009-07-10
CVE-2009-2430 [MEDIUM] CVE-2009-2430: Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv
Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Auditing is enabled, allows local users with an RBAC execution profile for auditconfig to gain privileges via unknown attack vectors.
nvd
CVE-2010-0271P4MEDIUMCVSS 4.6vsnv_51vsnv_52+79 more2010-01-08
CVE-2010-0271 [MEDIUM] CWE-264 CVE-2010-0271: hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspeci
hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.
nvd
CVE-2009-2187P4MEDIUMCVSS 4.9vsnv_67vsnv_68+25 more2009-06-25
CVE-2009-2187 [MEDIUM] CWE-399 CVE-2009-2187: Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solar
Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allow local users to cause a denial of service (memory consumption) via vectors related to the association of (a) DL_ENABMULTI_REQ and (b) DL_DISABMULTI_REQ messages with ARP messages.
nvd
CVE-2009-2711P4MEDIUMCVSS 4.9vsnv_01vsnv_02+117 more2009-08-07
CVE-2009-2711 [MEDIUM] CVE-2009-2711: XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.
nvd
CVE-2009-0838P4MEDIUMCVSS 4.9vsnv_88vsnv_89+14 more2009-03-06
CVE-2009-0838 [MEDIUM] CWE-399 CVE-2009-0838: The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not
The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.
nvd
CVE-2009-2488P4MEDIUMCVSS 4.9vsnv_102vsnv_103+16 more2009-07-16
CVE-2009-2488 [MEDIUM] CVE-2009-2488: Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_1
Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving "file operations."
nvd
CVE-2009-0069P4MEDIUMCVSS 4.9≤ snv_101vsnv_01+100 more2009-01-07
CVE-2009-0069 [MEDIUM] CWE-399 CVE-2009-0069: Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client i
Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.
nvd
CVE-2009-0926P4MEDIUMCVSS 4.9vbuild_snv_39vsnv_40+48 more2009-03-17
CVE-2009-0926 [MEDIUM] CWE-399 CVE-2009-0926: Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_
Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.
nvd
CVE-2009-3937P4MEDIUMCVSS 4.9vsnv_106vsnv_107+19 more2009-11-13
CVE-2009-3937 [MEDIUM] CWE-399 CVE-2009-3937: Memory leak in Solaris TCP sockets in Sun OpenSolaris snv_106 through snv_126 allows local users to
Memory leak in Solaris TCP sockets in Sun OpenSolaris snv_106 through snv_126 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors involving tcp_sendmsg processing "ancillary data."
nvd
CVE-2009-2135P4MEDIUMCVSS 4.9≤ snv_106vsnv_01+105 more2009-06-19
CVE-2009-2135 [MEDIUM] CWE-362 CVE-2009-2135: Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.
nvd
CVE-2009-0268P4MEDIUMCVSS 4.9≤ snv_102vsnv_01+100 more2009-01-26
CVE-2009-0268 [MEDIUM] CWE-362 CVE-2009-0268: Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenS
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
nvd