Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 1 of 22
CVE-2001-0797P2CRITICALCVSS 10.0ExploitedPoCv2.4v2.5+4 more2001-12-12
CVE-2001-0797 [CRITICAL] CVE-2001-0797: Buffer overflow in login in various System V based operating systems allows remote attackers to exec
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
nvd
CVE-2003-0201P2CRITICALCVSS 10.0ExploitedPoCv2.5.1v2.6+3 more2003-05-05
CVE-2003-0201 [CRITICAL] CVE-2003-0201: Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 an
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
nvd
CVE-1999-0502P2HIGHCVSS 7.5ExploitedPoCv2.61998-03-01
CVE-1999-0502 [HIGH] CVE-1999-0502: A Unix account has a default, null, blank, or missing password.
A Unix account has a default, null, blank, or missing password.
nvd
CVE-2003-0694P2CRITICALCVSS 10.0ExploitedPoCv2.6v7.0+2 more2003-10-06
CVE-2003-0694 [CRITICAL] CVE-2003-0694: The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
nvd
CVE-2001-0236P2CRITICALCVSS 10.0ExploitedPoCv2.6v7.0+1 more2001-05-03
CVE-2001-0236 [CRITICAL] CVE-2001-0236: Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute ar
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
nvd
CVE-2001-0554P2CRITICALCVSS 10.0ExploitedPoCv2.62001-08-14
CVE-2001-0554 [CRITICAL] CWE-120 CVE-2001-0554: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attack
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
nvd
CVE-2008-4556P2CRITICALCVSS 10.0PoCv8v92008-10-14
CVE-2008-4556 [CRITICAL] CWE-119 CVE-2008-4556: Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.
nvd
CVE-2007-5365P2HIGHCVSS 7.2PoCv8.0v9.0+1 more2007-10-11
CVE-2007-5365 [HIGH] CWE-119 CVE-2007-5365: Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 throug
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
nvd
CVE-2001-0779P2CRITICALCVSS 10.0PoCv2.6v7.0+1 more2001-10-18
CVE-2001-0779 [CRITICAL] CVE-2001-0779: Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers t
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
nvd
CVE-2003-0466P3CRITICALCVSS 9.8PoCv9.02003-08-27
CVE-2003-0466 [CRITICAL] CWE-193 CVE-2003-0466: Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may al
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU
nvd
CVE-2008-0964P2CRITICALCVSS 9.3PoCv8v9+1 more2008-08-08
CVE-2008-0964 [CRITICAL] CWE-119 CVE-2008-0964: Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before sn
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.
nvd
CVE-2003-0161P3CRITICALCVSS 10.0PoCv2.4v2.5+5 more2003-04-02
CVE-2003-0161 [CRITICAL] CVE-2003-0161: The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not proper
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary
nvd
CVE-2004-0790P3MEDIUMCVSS 5.0PoCv9.0v10.02005-04-12
CVE-2004-0790 [MEDIUM] CVE-2004-0790: Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are relate
nvd
CVE-2002-0033P3CRITICALCVSS 10.0PoCv2.5.1v2.6+2 more2002-05-29
CVE-2002-0033 [CRITICAL] CVE-2002-0033: Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to ex
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.
nvd
CVE-1999-0003P3CRITICALCVSS 10.0PoCv2.61998-04-01
CVE-1999-0003 [CRITICAL] CVE-1999-0003: Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
nvd
CVE-1999-0977P3CRITICALCVSS 10.0PoCv2.5v2.5.1+2 more1999-12-10
CVE-1999-0977 [CRITICAL] CVE-1999-0977: Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PR
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
nvd
CVE-2002-1317P3HIGHCVSS 7.5PoCv2.5.1v2.6+3 more2002-12-11
CVE-2002-1317 [HIGH] CVE-2002-1317: Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allow
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
nvd
CVE-1999-0009P3CRITICALCVSS 10.0PoCv2.5v2.5.1+1 more1998-04-08
CVE-1999-0009 [CRITICAL] CVE-1999-0009: Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
nvd
CVE-2002-0436P3CRITICALCVSS 10.0PoCv7.0v8.02002-07-26
CVE-2002-0436 [CRITICAL] CVE-2002-0436: sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitra
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.
nvd
CVE-2000-0844P3CRITICALCVSS 10.0PoCv2.62000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
1 / 22Next →