Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 12 of 22
CVE-2002-0089P4HIGHCVSS 7.2v2.6v8.02002-03-15
CVE-2002-0089 [HIGH] CVE-2002-0089: Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.
nvd
CVE-1999-0339P4HIGHCVSS 7.2v2.5v2.5.1+1 more1998-08-01
CVE-1999-0339 [HIGH] CVE-1999-0339: Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges,
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
nvd
CVE-1999-0135P4HIGHCVSS 7.2v2.5v2.5.11996-07-25
CVE-1999-0135 [HIGH] CVE-1999-0135: admintool in Solaris allows a local user to write to arbitrary files and gain root access.
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
nvd
CVE-2003-1068P4HIGHCVSS 7.2v2.6v7.0+2 more2003-06-06
CVE-2003-1068 [HIGH] CVE-2003-1068: Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges,
Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.
nvd
CVE-2007-2529P4HIGHCVSS 7.2v10.02007-05-09
CVE-2007-2529 [HIGH] CVE-2007-2529: Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local us
Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.
nvd
CVE-2006-0190P4HIGHCVSS 7.2v9.0v10.02006-01-13
CVE-2006-0190 [HIGH] CVE-2006-0190: Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain pr
Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.
nvd
CVE-2002-1590P4HIGHCVSS 7.2v8.02002-10-29
CVE-2002-1590 [HIGH] CWE-264 CVE-2002-1590: The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and
The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
nvd
CVE-2006-0769P4HIGHCVSS 7.2v10.02006-02-18
CVE-2006-0769 [HIGH] CVE-2006-0769: Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerber
Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.
nvd
CVE-1999-0952P4HIGHCVSS 7.2v2.61999-01-28
CVE-1999-0952 [HIGH] CVE-1999-0952: Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
nvd
CVE-2006-6494P4MEDIUMCVSS 6.6v9.0v10.02006-12-13
CVE-2006-6494 [MEDIUM] CVE-2006-6494: Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execu
Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.
nvd
CVE-2008-6024P4MEDIUMCVSS 5.4v102009-02-02
CVE-2008-6024 [MEDIUM] CWE-399 CVE-2008-6024: Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris
Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris before snv_37, when automountd is used, allows user-assisted remote attackers to cause a denial of service (unresponsive NFS filesystems) via unknown vectors.
nvd
CVE-2003-1066P4MEDIUMCVSS 5.0v2.6v7.0+2 more2003-12-31
CVE-2003-1066 [MEDIUM] CVE-2003-1066: Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a de
Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.
nvd
CVE-1999-0189P4HIGHCVSS 7.5v2.4v2.5+1 more1997-06-04
CVE-1999-0189 [HIGH] CVE-1999-0189: Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard po
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
nvd
CVE-2003-0914P4MEDIUMCVSS 4.3v7.0v8.0+1 more2003-12-15
CVE-2003-0914 [MEDIUM] CVE-2003-0914: ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
nvd
CVE-2006-5201P4MEDIUMCVSS 4.0v9.0v10.02006-10-10
CVE-2006-5201 [MEDIUM] CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier,
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which all
nvd
CVE-2002-1296P4HIGHCVSS 7.2v2.6v7.0+2 more2002-12-23
CVE-2002-1296 [HIGH] CVE-2002-1296: Directory traversal vulnerability in priocntl system call in Solaris does allows local users to exec
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
nvd
CVE-2003-1057P4HIGHCVSS 7.2v2.6v7.0+2 more2003-12-08
CVE-2003-1057 [HIGH] CVE-2003-1057: Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow loca
Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.
nvd
CVE-2002-0088P4HIGHCVSS 7.2v2.6v8.02002-03-15
CVE-2002-0088 [HIGH] CVE-2002-0088: Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
nvd
CVE-1999-1027P4HIGHCVSS 7.2v2.61998-05-07
CVE-1999-1027 [HIGH] CVE-1999-1027: Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to g
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
nvd
CVE-2000-0055P4HIGHCVSS 7.2v2.4v2.5+3 more2000-01-06
CVE-2000-0055 [HIGH] CVE-2000-0055: Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n opti
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
nvd