Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 14 of 22
CVE-2002-1871P4HIGHCVSS 7.2v2.62002-12-31
CVE-2002-1871 [HIGH] CVE-2002-1871: pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
nvd
CVE-1999-0139P4HIGHCVSS 7.2v2.5v2.5.1+1 more1998-12-12
CVE-1999-0139 [HIGH] CVE-1999-0139: Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
nvd
CVE-2003-1076P4HIGHCVSS 7.2v7.0v8.0+1 more2003-12-31
CVE-2003-1076 [HIGH] CVE-2003-1076: Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of se
Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.
nvd
CVE-2003-1056P4HIGHCVSS 7.2v2.6v7.0+1 more2003-12-11
CVE-2003-1056 [HIGH] CVE-2003-1056: The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary file
The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-1999-0024P4MEDIUMCVSS 5.0v2.4v2.5+2 more1997-08-13
CVE-1999-0024 [MEDIUM] CVE-1999-0024: DNS cache poisoning via BIND, by predictable query IDs.
DNS cache poisoning via BIND, by predictable query IDs.
nvd
CVE-2007-3283P4MEDIUMCVSS 6.8v8.0v9.02007-06-19
CVE-2007-3283 [MEDIUM] CVE-2007-3283: GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, doe
GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.
nvd
CVE-2003-0058P4MEDIUMCVSS 5.0v8.0v9.02003-02-19
CVE-2003-0058 [MEDIUM] CVE-2003-0058: MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
nvd
CVE-2008-1356P4MEDIUMCVSS 6.3v102008-03-17
CVE-2008-1356 [MEDIUM] CWE-287 CVE-2008-1356: Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using th
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.
nvd
CVE-2002-1345P4MEDIUMCVSS 5.0v2.6v7.02002-12-23
CVE-2002-1345 [MEDIUM] CVE-2002-1345: Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious F
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
nvd
CVE-2006-4139P4MEDIUMCVSS 5.4v10.02006-08-14
CVE-2006-4139 [MEDIUM] CVE-2006-4139: Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via un
Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via unspecified vectors related to ifconfig and either netstat or SNMP queries.
nvd
CVE-2005-0447P4MEDIUMCVSS 5.0v9.02005-02-15
CVE-2005-0447 [MEDIUM] CVE-2005-0447: Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certa
Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.
nvd
CVE-2009-2029P4MEDIUMCVSS 5.0v8v9+4 more2009-06-11
CVE-2009-2029 [MEDIUM] CVE-2009-2029: Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, a
Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.
nvd
CVE-1999-0982P4HIGHCVSS 7.2v8.01999-12-05
CVE-1999-0982 [HIGH] CVE-1999-0982: The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in
The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.
nvd
CVE-2004-0800P4MEDIUMCVSS 4.6v8.0v9.02004-08-24
CVE-2004-0800 [MEDIUM] CVE-2004-0800: Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain pri
Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.
nvd
CVE-2005-3099P4MEDIUMCVSS 4.6v9.0v10.02005-09-28
CVE-2005-3099 [MEDIUM] CVE-2005-3099: Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows lo
Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.
nvd
CVE-2006-3664P4MEDIUMCVSS 5.0v8.0v9.0+1 more2006-07-18
CVE-2006-3664 [MEDIUM] CVE-2006-3664: Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attacker
Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.
nvd
CVE-2004-1348P4MEDIUMCVSS 5.0v8.02004-09-06
CVE-2004-1348 [MEDIUM] CVE-2004-1348: Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service
Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).
nvd
CVE-2008-5550P4MEDIUMCVSS 4.3v102008-12-12
CVE-2008-5550 [MEDIUM] CVE-2008-5550: Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.
nvd
CVE-2004-1393P4MEDIUMCVSS 5.0v2.62004-12-31
CVE-2004-1393 [MEDIUM] CVE-2004-1393: Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local
Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).
nvd
CVE-2005-0426P4MEDIUMCVSS 5.0v9.02005-05-02
CVE-2005-0426 [MEDIUM] CVE-2005-0426: Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic
Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.
nvd