Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 17 of 22
CVE-2009-0168P4MEDIUMCVSS 4.9v102009-01-16
CVE-2009-0168 [MEDIUM] CVE-2009-0168: Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows
Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.
nvd
CVE-2009-1673P4MEDIUMCVSS 4.9v92009-05-18
CVE-2009-1673 [MEDIUM] CVE-2009-1673: The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat
The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.
nvd
CVE-2007-5632P4MEDIUMCVSS 4.9v8.0v9.0+1 more2007-10-23
CVE-2007-5632 [MEDIUM] CVE-2007-5632: Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to
Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions.
nvd
CVE-2009-0480P4MEDIUMCVSS 4.9v8v9+1 more2009-02-09
CVE-2009-0480 [MEDIUM] CWE-189 CVE-2009-0480: The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper a
The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.
nvd
CVE-2008-1205P4MEDIUMCVSS 4.9v102008-03-08
CVE-2008-1205 [MEDIUM] CVE-2008-1205: Unspecified vulnerability in the ipsecah kernel module in Sun Solaris 10, when a key management daem
Unspecified vulnerability in the ipsecah kernel module in Sun Solaris 10, when a key management daemon for IPsec security associations is running, allows local users to cause a denial of service (panic) via unspecified vectors.
nvd
CVE-2009-2912P4MEDIUMCVSS 4.9v8v9+1 more2009-08-21
CVE-2009-2912 [MEDIUM] CVE-2009-2912: The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv
The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.
nvd
CVE-2009-0132P4MEDIUMCVSS 4.9v8v9+1 more2009-01-15
CVE-2009-0132 [MEDIUM] CWE-189 CVE-2009-0132: Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bi
Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).
nvd
CVE-2007-4495P4MEDIUMCVSS 4.9v8.0v9.0+1 more2007-08-23
CVE-2007-4495 [MEDIUM] CVE-2007-4495: Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 200708
Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 20070821 allows local users to cause a denial of service (system panic) via an unspecified ioctl function, aka Bug 6433124.
nvd
CVE-2007-4492P4MEDIUMCVSS 4.9v8.0v9.0+1 more2007-08-23
CVE-2007-4492 [MEDIUM] CVE-2007-4492: Multiple unspecified vulnerabilities in the ata disk driver in Sun Solaris 8, 9, and 10 on the x86 p
Multiple unspecified vulnerabilities in the ata disk driver in Sun Solaris 8, 9, and 10 on the x86 platform before 20070821 allow local users to cause a denial of service (system panic) via unspecified ioctl functions, aka Bug 6433123.
nvd
CVE-2009-2644P4MEDIUMCVSS 4.9v9.0v10.02009-07-29
CVE-2009-2644 [MEDIUM] CWE-362 CVE-2009-2644: Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_
Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."
nvd
CVE-2009-0870P4MEDIUMCVSS 4.7v10.02009-03-10
CVE-2009-0870 [MEDIUM] CWE-399 CVE-2009-0870: The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local
The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.
nvd
CVE-2009-0925P4MEDIUMCVSS 4.7v10.02009-03-17
CVE-2009-0925 [MEDIUM] CWE-399 CVE-2009-0925: Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through s
Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through snv_85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6425723.
nvd
CVE-2009-0924P4MEDIUMCVSS 4.7v10.02009-03-17
CVE-2009-0924 [MEDIUM] CWE-399 CVE-2009-0924: Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x
Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.
nvd
CVE-2007-6216P4MEDIUMCVSS 4.7v102007-12-04
CVE-2007-6216 [MEDIUM] CWE-362 CVE-2007-6216: Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Sola
Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.
nvd
CVE-2006-6275P4MEDIUMCVSS 4.7v8.0v9.0+1 more2006-12-04
CVE-2006-6275 [MEDIUM] CWE-362 CVE-2006-6275: Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of ser
Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function and SIGKILL and /proc PCAGENT signals.
nvd
CVE-2008-1684P4MEDIUMCVSS 4.7v102008-04-06
CVE-2008-1684 [MEDIUM] CWE-59 CVE-2008-1684: inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary fil
inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.
nvd
CVE-2008-1780P4MEDIUMCVSS 4.6v102008-04-14
CVE-2008-1780 [MEDIUM] CWE-264 CVE-2008-1780: Unspecified vulnerability in the labeled networking functionality in Solaris 10 Trusted Extensions a
Unspecified vulnerability in the labeled networking functionality in Solaris 10 Trusted Extensions allows applications in separate labeling zones to bypass labeling restrictions via unknown vectors.
nvd
CVE-2006-2064P4MEDIUMCVSS 4.6v10.02006-04-27
CVE-2006-2064 [MEDIUM] CVE-2006-2064: Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain
Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain privileges or cause a denial of service (application failure) via unknown attack vectors that involve the getpwnam family of non-reentrant functions.
nvd
CVE-2004-1394P4MEDIUMCVSS 4.6v9.02004-12-31
CVE-2004-1394 [MEDIUM] CVE-2004-1394: The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
nvd
CVE-2009-3706P4MEDIUMCVSS 4.4v10v10.02009-10-16
CVE-2009-3706 [MEDIUM] CVE-2009-3706: Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv_100 through s
Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv_100 through snv_117, allows local users to bypass intended limitations of the file_chown_self privilege via certain uses of the chown system call.
nvd