Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
0
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 17 of 22
CVE-2001-1555MEDIUMCVSS 4.6v8.02001-12-31
CVE-2001-1555 [MEDIUM] CVE-2001-1555: pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of termi
pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.
nvd
CVE-2001-1503LOWCVSS 2.1v2.5v2.5.1+3 more2001-12-31
CVE-2001-1503 [LOW] CVE-2001-1503: The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
nvd
CVE-2001-0797CRITICALCVSS 10.0PoCv2.4v2.5+4 more2001-12-12
CVE-2001-0797 [CRITICAL] CVE-2001-0797: Buffer overflow in login in various System V based operating systems allows remote attackers to exec
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
nvd
CVE-2001-0779CRITICALCVSS 10.0PoCv2.6v7.0+1 more2001-10-18
CVE-2001-0779 [CRITICAL] CVE-2001-0779: Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers t
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
nvd
CVE-2001-1414HIGHCVSS 7.5v2.5.1v2.6+2 more2001-10-09
CVE-2001-1414 [HIGH] CVE-2001-1414: The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access,
The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
nvd
CVE-2001-0686MEDIUMCVSS 4.6v5.8v8.02001-09-20
CVE-2001-0686 [MEDIUM] CVE-2001-0686: Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a
Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.
nvd
CVE-2001-0554CRITICALCVSS 10.0PoCv2.62001-08-14
CVE-2001-0554 [CRITICAL] CWE-120 CVE-2001-0554: Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attack
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
nvd
CVE-2001-0526MEDIUMCVSS 4.6PoCv8.02001-08-14
CVE-2001-0526 [MEDIUM] CVE-2001-0526: Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local att
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.
nvd
CVE-2001-0548MEDIUMCVSS 4.6PoCv2.62001-08-14
CVE-2001-0548 [MEDIUM] CVE-2001-0548: Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL en
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
nvd
CVE-2001-0565MEDIUMCVSS 4.6PoCv2.5v2.5.1+3 more2001-08-14
CVE-2001-0565 [MEDIUM] CVE-2001-0565: Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privile
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
nvd
CVE-2001-0594MEDIUMCVSS 4.6PoCv7.0v8.02001-08-02
CVE-2001-0594 [MEDIUM] CVE-2001-0594: kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privilege
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.
nvd
CVE-2001-0353CRITICALCVSS 10.0v2.6v7.0+1 more2001-07-21
CVE-2001-0353 [CRITICAL] CVE-2001-0353: Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remot
Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
nvd
CVE-2001-1076HIGHCVSS 7.2PoCv2.5v2.5.1+3 more2001-07-05
CVE-2001-1076 [HIGH] CVE-2001-1076: Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
nvd
CVE-2001-0423HIGHCVSS 7.2PoCv7.02001-07-02
CVE-2001-0423 [HIGH] CVE-2001-0423: Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.
nvd
CVE-2001-0426HIGHCVSS 7.2PoCv2.6v7.0+1 more2001-07-02
CVE-2001-0426 [HIGH] CVE-2001-0426: Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
nvd
CVE-2001-0422HIGHCVSS 7.2PoCv2.62001-07-02
CVE-2001-0422 [HIGH] CVE-2001-0422: Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands vi
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2001-0421MEDIUMCVSS 6.4PoCv2.62001-07-02
CVE-2001-0421 [MEDIUM] CVE-2001-0421: FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the ro
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
nvd
CVE-2001-0401HIGHCVSS 7.2PoCv2.62001-06-18
CVE-2001-0401 [HIGH] CVE-2001-0401: Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2001-0236CRITICALCVSS 10.0PoCv2.6v7.0+1 more2001-05-03
CVE-2001-0236 [CRITICAL] CVE-2001-0236: Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute ar
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
nvd
CVE-2001-0165HIGHCVSS 7.2PoCv7.0v8.02001-05-03
CVE-2001-0165 [HIGH] CVE-2001-0165: Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privi
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
nvd