cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 11 of 22
CVE-2003-1074P4HIGHCVSS 7.2v9.02003-03-28
CVE-2003-1074 [HIGH] CVE-2003-1074: Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges. Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.
nvd
CVE-2009-4075P4MEDIUMCVSS 5.0v102009-11-25
CVE-2009-4075 [MEDIUM] CVE-2009-4075: Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors that trigger a "dangling sshd authentication thread."
nvd
CVE-2007-0914P4HIGHCVSS 7.1v10.02007-02-14
CVE-2007-0914 [HIGH] CVE-2007-0914: Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of serv Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.
nvd
CVE-2007-5726P4MEDIUMCVSS 6.8v10.02007-10-30
CVE-2007-5726 [MEDIUM] CVE-2007-5726: Unspecified vulnerability in the Stream Control Transmission Protocol (sctp) functionality in Sun So Unspecified vulnerability in the Stream Control Transmission Protocol (sctp) functionality in Sun Solaris 10, when at least one SCTP socket is in the LISTEN state, allows remote attackers to cause a denial of service (panic) via unspecified vectors related to "INIT processing."
nvd
CVE-1999-0318P4HIGHCVSS 7.2v2.61997-03-01
CVE-1999-0318 [HIGH] CVE-1999-0318: Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable. Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
nvd
CVE-2004-0780P4HIGHCVSS 7.2v8.0v9.02004-12-31
CVE-2004-0780 [HIGH] CVE-2004-0780: Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.
nvd
CVE-2004-1352P4HIGHCVSS 7.2v7.0v8.0+1 more2004-12-01
CVE-2004-1352 [HIGH] CVE-2004-1352: Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbit Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.
nvd
CVE-2006-0901P4HIGHCVSS 7.2v8.0v9.0+1 more2006-02-27
CVE-2006-0901 [HIGH] CVE-2006-0901: Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attacker Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.
nvd
CVE-2003-0092P4HIGHCVSS 7.2v2.6v9.02003-04-02
CVE-2003-0092 [HIGH] CVE-2003-0092: Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to ga Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.
nvd
CVE-2009-3851P4HIGHCVSS 7.2v10.02009-11-03
CVE-2009-3851 [HIGH] CVE-2009-3851: Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command for the XScreenSaver application, which makes it easier for physically proximate attackers to access an unattended workstation for which the intended screen locking did not occur, related to the "restart daemon."
nvd
CVE-2008-3875P4HIGHCVSS 7.2v8v9+1 more2008-09-02
CVE-2008-3875 [HIGH] CWE-264 CVE-2008-3875: The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass ch The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.
nvd
CVE-2004-1353P4HIGHCVSS 7.2v8.0v9.02004-10-19
CVE-2004-1353 [HIGH] CVE-2004-1353: Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), a Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.
nvd
CVE-2007-0470P4HIGHCVSS 7.2v9.0v10.02007-01-24
CVE-2007-0470 [HIGH] CVE-2007-0470: Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uu Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.
nvd
CVE-2007-0503P4MEDIUMCVSS 6.9v9.02007-01-25
CVE-2007-0503 [MEDIUM] CVE-2007-0503: Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local user Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.
nvd
CVE-2006-6495P4MEDIUMCVSS 6.6v9.0v10.02006-12-13
CVE-2006-6495 [MEDIUM] CVE-2006-6495: Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arb Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function. NOTE: this issue normally does not cross privilege boundaries, except in cases of external introduction of malicious message files, or if
nvd
CVE-2004-1357P4MEDIUMCVSS 5.0v9.02004-04-07
CVE-2004-1357 [MEDIUM] CVE-2004-1357: The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD i The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.
nvd
CVE-2002-1980P4HIGHCVSS 7.2v2.5.1v2.6+2 more2002-12-31
CVE-2002-1980 [HIGH] CVE-2002-1980: Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.
nvd
CVE-2003-1082P4HIGHCVSS 7.2v2.6v7.0+2 more2003-12-31
CVE-2003-1082 [HIGH] CVE-2003-1082: Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.
nvd
CVE-2003-1067P4HIGHCVSS 7.2v2.6v7.0+2 more2003-06-19
CVE-2003-1067 [HIGH] CVE-2003-1067: Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
nvd
CVE-1999-1419P4HIGHCVSS 7.2v2.41997-07-30
CVE-1999-1419 [HIGH] CVE-1999-1419: Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gai Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.
nvd
Sun Solaris vulnerabilities | cvebase