cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 15 of 22
CVE-2003-1060P4MEDIUMCVSS 5.0v7.0v8.0+1 more2003-10-27
CVE-2003-1060 [MEDIUM] CVE-2003-1060: The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS pan The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.
nvd
CVE-2007-4070P4MEDIUMCVSS 4.9v8.0v9.0+1 more2007-07-30
CVE-2007-4070 [MEDIUM] CVE-2007-4070: Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 200 Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.
nvd
CVE-1999-0188P4HIGHCVSS 7.2v2.4v2.5+2 more1998-12-17
CVE-1999-0188 [HIGH] CVE-1999-0188: The passwd command in Solaris can be subjected to a denial of service. The passwd command in Solaris can be subjected to a denial of service.
nvd
CVE-2008-5699P4MEDIUMCVSS 4.6v10.02008-12-22
CVE-2008-5699 [MEDIUM] CWE-264 CVE-2008-5699: The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv_50 through snv_104 does n The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv_50 through snv_104 does not properly check permissions, which allows local users to gain privileges and obtain sensitive information via unspecified vectors.
nvd
CVE-2005-1124P4MEDIUMCVSS 4.6v9.02005-05-02
CVE-2005-1124 [MEDIUM] CVE-2005-1124: Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.
nvd
CVE-2009-1207P4MEDIUMCVSS 4.4v8v9+1 more2009-04-01
CVE-2009-1207 [MEDIUM] CWE-362 CVE-2009-1207: Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_ Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.
nvd
CVE-2003-1079P4MEDIUMCVSS 5.0v2.5.1v2.6+3 more2003-02-18
CVE-2003-1079 [MEDIUM] CVE-2003-1079: Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.
nvd
CVE-2002-1228P4MEDIUMCVSS 5.0v2.5.1v7.0+2 more2002-10-28
CVE-2002-1228 [MEDIUM] CVE-2002-1228: Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a deni Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.
nvd
CVE-2002-0085P4MEDIUMCVSS 5.0v2.6v8.02002-03-15
CVE-2002-0085 [MEDIUM] CVE-2002-0085: cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via a cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.
nvd
CVE-2003-1069P4MEDIUMCVSS 5.0v2.6v7.0+2 more2003-06-03
CVE-2003-1069 [MEDIUM] CVE-2003-1069: The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial o The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).
nvd
CVE-2003-1070P4MEDIUMCVSS 5.0v2.6v7.0+2 more2003-04-28
CVE-2003-1070 [MEDIUM] CVE-2003-1070: Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).
nvd
CVE-2003-1075P4MEDIUMCVSS 5.0v2.6v7.0+2 more2003-01-27
CVE-2003-1075 [MEDIUM] CVE-2003-1075: Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.
nvd
CVE-2002-1585P4MEDIUMCVSS 5.0v8.0v9.02002-11-08
CVE-2002-1585 [MEDIUM] CVE-2002-1585: Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers t Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfaces to stop responding to TCP traffic.
nvd
CVE-2006-3606P4MEDIUMCVSS 5.0v9.02006-07-18
CVE-2006-3606 [MEDIUM] CVE-2006-3606: Unspecified vulnerability in Sun Solaris X Inter Client Exchange library (libICE) on Solaris 8 and 9 Unspecified vulnerability in Sun Solaris X Inter Client Exchange library (libICE) on Solaris 8 and 9 allows context-dependent attackers to cause a denial of service (application crash) to applications that use the library.
nvd
CVE-2006-4303P4LOWCVSS 2.6v10.02006-08-23
CVE-2006-4303 [LOW] CVE-2006-4303: Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun Solaris 10 allows remote attackers Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun Solaris 10 allows remote attackers to cause a denial of service ("tight loop" and CPU consumption for listener applications) via unknown vectors related to TCP fusion (do_tcp_fusion).
nvd
CVE-2004-1358P4MEDIUMCVSS 5.0v9.02004-03-12
CVE-2004-1358 [MEDIUM] CVE-2004-1358: The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.
nvd
CVE-2005-1591P4MEDIUMCVSS 5.0v7.0v8.0+1 more2005-05-16
CVE-2005-1591 [MEDIUM] CVE-2005-1591: Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of se Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.
nvd
CVE-2009-0874P4MEDIUMCVSS 4.9v8v9+1 more2009-03-12
CVE-2009-0874 [MEDIUM] CWE-399 CVE-2009-0874: Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 1 Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door ser
nvd
CVE-2009-0346P4MEDIUMCVSS 4.9v9v102009-01-29
CVE-2009-0346 [MEDIUM] CWE-310 CVE-2009-0346: The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solari The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
nvd
CVE-2002-2197P4HIGHCVSS 7.2v8.02002-12-31
CVE-2002-2197 [HIGH] CVE-2002-2197: Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel pan Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference.
nvd