Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 13 of 22
CVE-2009-0875P4MEDIUMCVSS 6.9v8v9+1 more2009-03-12
CVE-2009-0875 [MEDIUM] CWE-362 CVE-2009-0875: Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris bef
Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
nvd
CVE-2007-2882P4MEDIUMCVSS 5.0v8.0v9.0+1 more2007-05-30
CVE-2007-2882 [MEDIUM] CVE-2007-2882: Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when
Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.
nvd
CVE-2006-3920P4MEDIUMCVSS 5.0v9.0v10.02006-07-28
CVE-2006-3920 [MEDIUM] CVE-2006-3920: The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause
The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause a denial of service (resource exhaustion) via a TCP packet with an incorrect sequence number, which triggers an ACK storm.
nvd
CVE-2009-0267P4MEDIUMCVSS 5.0v9v102009-01-26
CVE-2009-0267 [MEDIUM] CVE-2009-0267: libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, whi
libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
nvd
CVE-2006-4117P4MEDIUMCVSS 5.4v10.02006-08-14
CVE-2006-4117 [MEDIUM] CVE-2006-4117: The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote
The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a large number of TCP connections ("heavy TCP/IP loads"). NOTE: the original report specifies the function name as "drain_squeue," but this is likely incorrect.
nvd
CVE-2006-3728P4MEDIUMCVSS 6.8v10.02006-07-21
CVE-2006-3728 [MEDIUM] CVE-2006-3728: Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and wi
Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption."
nvd
CVE-2002-0090P4HIGHCVSS 7.2v8.02002-03-15
CVE-2002-0090 [HIGH] CVE-2002-0090: Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbit
Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.
nvd
CVE-2001-0190P4HIGHCVSS 7.2v2.62001-03-26
CVE-2001-0190 [HIGH] CVE-2001-0190: Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, all
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
nvd
CVE-2001-0124P4HIGHCVSS 7.2v2.62001-03-12
CVE-2001-0124 [HIGH] CVE-2001-0124: Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileg
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
nvd
CVE-2009-0319P4MEDIUMCVSS 6.9v8v9+1 more2009-01-28
CVE-2009-0319 [MEDIUM] CVE-2009-0319: Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSo
Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."
nvd
CVE-2010-0310P4MEDIUMCVSS 6.8v10.02010-01-14
CVE-2010-0310 [MEDIUM] CWE-264 CVE-2010-0310: Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to om
Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.
nvd
CVE-2002-1199P4MEDIUMCVSS 5.0v9.02002-10-28
CVE-2002-1199 [MEDIUM] CVE-2002-1199: The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to r
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
nvd
CVE-1999-0300P4HIGHCVSS 7.5v2.4v2.5+1 more1997-10-01
CVE-1999-0300 [HIGH] CVE-1999-0300: nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
nvd
CVE-1999-0295P4HIGHCVSS 7.2v2.4v2.5+1 more1997-10-01
CVE-1999-0295 [HIGH] CVE-1999-0295: Solaris sysdef command allows local users to read kernel memory, potentially leading to root privile
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
nvd
CVE-2008-2538P4MEDIUMCVSS 6.9v8v9+1 more2008-06-03
CVE-2008-2538 [MEDIUM] CWE-362 CVE-2008-2538: Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, all
Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.
nvd
CVE-2004-1354P4MEDIUMCVSS 5.0v8.0v9.02004-05-14
CVE-2004-1354 [MEDIUM] CWE-22 CVE-2004-1354: The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages w
The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.
nvd
CVE-2008-5661P4MEDIUMCVSS 5.4v102008-12-17
CVE-2008-5661 [MEDIUM] CWE-399 CVE-2008-5661: The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain pa
The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.
nvd
CVE-2008-5684P4MEDIUMCVSS 5.0v8v9+1 more2008-12-19
CVE-2008-5684 [MEDIUM] CWE-399 CVE-2008-5684: Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 throu
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
nvd
CVE-2006-3968P4MEDIUMCVSS 5.0v10.02006-08-01
CVE-2006-3968 [MEDIUM] CVE-2006-3968: The crypto provider in Sun Solaris 10 3/05 HW2 without patch 121236-01, when running on Sun Fire T20
The crypto provider in Sun Solaris 10 3/05 HW2 without patch 121236-01, when running on Sun Fire T2000 platforms, incorrectly verifies a DSA signature, which might prevent applications from detecting that the data has been modified.
nvd
CVE-2009-2283P4MEDIUMCVSS 4.3v102009-07-01
CVE-2009-2283 [MEDIUM] CWE-79 CVE-2009-2283: Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console
Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd