Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 16 of 22
CVE-1999-0296P4HIGHCVSS 7.2v2.61998-02-01
CVE-1999-0296 [HIGH] CVE-1999-0296: Solaris volrmmount program allows attackers to read any file.
Solaris volrmmount program allows attackers to read any file.
nvd
CVE-2009-1933P4MEDIUMCVSS 4.7v8v9+1 more2009-06-05
CVE-2009-1933 [MEDIUM] CWE-255 CVE-2009-1933: Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage crede
Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.
nvd
CVE-2004-1359P4MEDIUMCVSS 4.6v2.6v7.0+2 more2004-03-04
CVE-2004-1359 [MEDIUM] CVE-2004-1359: Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbi
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.
nvd
CVE-2009-2430P4MEDIUMCVSS 4.6v8v9+1 more2009-07-10
CVE-2009-2430 [MEDIUM] CVE-2009-2430: Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv
Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Auditing is enabled, allows local users with an RBAC execution profile for auditconfig to gain privileges via unknown attack vectors.
nvd
CVE-2007-3069P4MEDIUMCVSS 4.6v10.02007-06-06
CVE-2007-3069 [MEDIUM] CVE-2007-3069: xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology suppo
xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.
nvd
CVE-2007-0393P4MEDIUMCVSS 4.6v9.02007-01-19
CVE-2007-0393 [MEDIUM] CVE-2007-0393: Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which
Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.
nvd
CVE-2005-1887P4MEDIUMCVSS 4.6v10.02005-06-09
CVE-2005-1887 [MEDIUM] CVE-2005-1887: Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local
Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.
nvd
CVE-2005-0109P4MEDIUMCVSS 5.6v7.0v8.0+2 more2005-03-05
CVE-2005-0109 [MEDIUM] CVE-2005-0109: Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pen
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
nvd
CVE-2000-0030P4MEDIUMCVSS 5.0v7.01999-12-22
CVE-2000-0030 [MEDIUM] CVE-2000-0030: Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /v
Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.
nvd
CVE-2009-2187P4MEDIUMCVSS 4.9v10.02009-06-25
CVE-2009-2187 [MEDIUM] CWE-399 CVE-2009-2187: Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solar
Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allow local users to cause a denial of service (memory consumption) via vectors related to the association of (a) DL_ENABMULTI_REQ and (b) DL_DISABMULTI_REQ messages with ARP messages.
nvd
CVE-2009-2711P4MEDIUMCVSS 4.9v9.0v10+1 more2009-08-07
CVE-2009-2711 [MEDIUM] CVE-2009-2711: XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when
XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.
nvd
CVE-2009-2488P4MEDIUMCVSS 4.9v102009-07-16
CVE-2009-2488 [MEDIUM] CVE-2009-2488: Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_1
Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving "file operations."
nvd
CVE-2009-0069P4MEDIUMCVSS 4.9v102009-01-07
CVE-2009-0069 [MEDIUM] CWE-399 CVE-2009-0069: Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client i
Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.
nvd
CVE-2009-0926P4MEDIUMCVSS 4.9v102009-03-17
CVE-2009-0926 [MEDIUM] CWE-399 CVE-2009-0926: Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_
Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.
nvd
CVE-2009-2135P4MEDIUMCVSS 4.9v10.02009-06-19
CVE-2009-2135 [MEDIUM] CWE-362 CVE-2009-2135: Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.
nvd
CVE-2009-0268P4MEDIUMCVSS 4.9v8v9+1 more2009-01-26
CVE-2009-0268 [MEDIUM] CWE-362 CVE-2009-0268: Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenS
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
nvd
CVE-2002-2089P4MEDIUMCVSS 4.6v9.02002-12-31
CVE-2002-2089 [MEDIUM] CVE-2002-2089: Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long comman
Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.
nvd
CVE-2008-0730P4MEDIUMCVSS 4.6v102008-02-12
CVE-2008-0730 [MEDIUM] CWE-264 CVE-2008-0730: The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods
The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.
nvd
CVE-2007-0668P4MEDIUMCVSS 6.2v10.02007-02-02
CVE-2007-0668 [MEDIUM] CVE-2007-0668: The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and
The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of service.
nvd
CVE-1999-0054P4MEDIUMCVSS 5.0v2.4v2.5+2 more1998-06-10
CVE-1999-0054 [MEDIUM] CVE-1999-0054: Sun's ftpd daemon can be subjected to a denial of service.
Sun's ftpd daemon can be subjected to a denial of service.
nvd