cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 19 of 22
CVE-1999-0132P4LOWCVSS 2.1v2.41996-08-15
CVE-1999-0132 [LOW] CVE-1999-0132: Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root acce Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
nvd
CVE-2009-3100P4MEDIUMCVSS 4.0v9v10+1 more2009-09-08
CVE-2009-3100 [MEDIUM] CVE-2009-3100: xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain
nvd
CVE-2006-4439P4LOWCVSS 3.6v10.02006-08-29
CVE-2006-4439 [LOW] CVE-2006-4439: pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.
nvd
CVE-2007-4732P4MEDIUMCVSS 4.9v8.0v9.0+1 more2007-09-06
CVE-2007-4732 [MEDIUM] CWE-20 CVE-2007-4732: Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Sol Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.
nvd
CVE-2007-3458P4MEDIUMCVSS 4.9v8.0v9.0+1 more2007-06-27
CVE-2007-3458 [MEDIUM] CVE-2007-3458: The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Na The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Name Service Caching Daemon (nscd) crash) via unspecified vectors.
nvd
CVE-2008-0836P4MEDIUMCVSS 4.9v9v102008-02-20
CVE-2008-0836 [MEDIUM] CVE-2008-0836: Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectur Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectures allows local users to cause a denial of service (panic) via unspecified vectors that trigger a NULL pointer dereference in the vuid3ps2 module, a different issue than CVE-2007-5319.
nvd
CVE-2007-6225P4MEDIUMCVSS 4.9v102007-12-04
CVE-2007-6225 [MEDIUM] CVE-2007-6225: Unspecified vulnerability in Sun Solaris 10, when 64bit mode is used on the x86 platform, allows loc Unspecified vulnerability in Sun Solaris 10, when 64bit mode is used on the x86 platform, allows local users in a Linux (lx) branded zone to cause a denial of service (panic) via unspecified vectors.
nvd
CVE-2007-5368P4MEDIUMCVSS 4.9v10.02007-10-11
CVE-2007-5368 [MEDIUM] CVE-2007-5368: Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local u Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local users to cause a denial of service (multiple application hang) via unspecified vectors.
nvd
CVE-2007-5367P4MEDIUMCVSS 4.9v10.02007-10-11
CVE-2007-5367 [MEDIUM] CWE-399 CVE-2007-5367: Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to c Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors.
nvd
CVE-2007-2990P4MEDIUMCVSS 4.9v10.02007-06-01
CVE-2007-2990 [MEDIUM] CVE-2007-2990: Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a d Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.
nvd
CVE-2006-3783P4MEDIUMCVSS 4.9v10.02006-07-24
CVE-2006-3783 [MEDIUM] CVE-2006-3783: Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors invol Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors involving (1) the /net mount point and (2) the "-hosts" map in a mount point.
nvd
CVE-2008-1317P4MEDIUMCVSS 4.9v102008-03-13
CVE-2008-1317 [MEDIUM] CVE-2008-1317: Unspecified vulnerability in the Inter-Process Communication (IPC) message queue subsystem in Sun So Unspecified vulnerability in the Inter-Process Communication (IPC) message queue subsystem in Sun Solaris 10 allows local users to cause a denial of service (reboot) via blocked I/O message queues.
nvd
CVE-2007-5118P4MEDIUMCVSS 4.7v8.0v9.0+1 more2007-09-27
CVE-2007-5118 [MEDIUM] CVE-2007-5118: Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.
nvd
CVE-2008-5111P4MEDIUMCVSS 4.7v102008-11-17
CVE-2008-5111 [MEDIUM] CVE-2008-5111: Unspecified vulnerability in the socket function in Sun Solaris 10 and OpenSolaris snv_57 through sn Unspecified vulnerability in the socket function in Sun Solaris 10 and OpenSolaris snv_57 through snv_91, when InfiniBand hardware is not installed, allows local users to cause a denial of service (panic) via unknown vectors, related to the socksdpv_close function.
nvd
CVE-2008-0933P4MEDIUMCVSS 4.7v10.02008-02-25
CVE-2008-0933 [MEDIUM] CWE-362 CVE-2008-0933: Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solari Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.
nvd
CVE-2008-3549P4MEDIUMCVSS 4.7v102008-08-07
CVE-2008-3549 [MEDIUM] CWE-399 CVE-2008-3549: Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris before snv_90 allows local users to cause a denial of service (system hang or panic) via unknown vectors.
nvd
CVE-2007-2465P4MEDIUMCVSS 4.7v9.02007-05-02
CVE-2007-2465 [MEDIUM] CVE-2007-2465: Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, wr Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.
nvd
CVE-2001-1503P4LOWCVSS 2.1v2.5v2.5.1+3 more2001-12-31
CVE-2001-1503 [LOW] CVE-2001-1503: The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
nvd
CVE-2002-1323P4MEDIUMCVSS 4.6v8.0v9.02002-12-11
CVE-2002-1323 [MEDIUM] CVE-2002-1323: Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
nvd
CVE-2001-1555P4MEDIUMCVSS 4.6v8.02001-12-31
CVE-2001-1555 [MEDIUM] CVE-2001-1555: pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of termi pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.
nvd
Sun Solaris vulnerabilities | cvebase