cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 2 of 22
CVE-1999-0210P3CRITICALCVSS 10.0PoCv2.4v2.5+1 more1997-11-26
CVE-1999-0210 [CRITICAL] CVE-1999-0210: Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
nvd
CVE-2008-5010P3CRITICALCVSS 10.0PoCv8v9+1 more2008-11-10
CVE-2008-5010 [CRITICAL] CVE-2008-5010: in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, all in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.
nvd
CVE-2005-4797P3MEDIUMCVSS 5.0PoCv7.0v8.0+2 more2005-12-31
CVE-2005-4797 [MEDIUM] CVE-2005-4797: Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via ".." sequences in an "Unlink data file" command.
nvd
CVE-2009-0304P3HIGHCVSS 7.8PoCv102009-01-27
CVE-2009-0304 [HIGH] CVE-2009-0304: The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attacker The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.
nvd
CVE-1999-0973P3CRITICALCVSS 10.0PoCv2.4v2.5+3 more1999-12-07
CVE-1999-0973 [CRITICAL] CVE-1999-0973: Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
nvd
CVE-1999-0696P3CRITICALCVSS 10.0PoCv2.5v2.61999-07-01
CVE-1999-0696 [CRITICAL] CVE-1999-0696: Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd). Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
nvd
CVE-1999-1588P3CRITICALCVSS 9.8PoCv2.4v2.5+1 more1999-12-31
CVE-1999-1588 [CRITICAL] CWE-119 CVE-1999-1588: Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to exe Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.
nvd
CVE-1999-0513P4MEDIUMCVSS 5.0PoCv2.4v2.5+2 more1998-01-05
CVE-1999-0513 [MEDIUM] CVE-1999-0513: ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denia ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
nvd
CVE-2002-0391P3CRITICALCVSS 9.8v2.6v9.02002-08-12
CVE-2002-0391 [CRITICAL] CWE-190 CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
nvd
CVE-2003-0027P3MEDIUMCVSS 5.0PoCv2.5.1v2.6+3 more2003-02-07
CVE-2003-0027 [MEDIUM] CVE-2003-0027: Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.
nvd
CVE-2007-0165P3HIGHCVSS 7.8PoCv9.02007-01-10
CVE-2007-0165 [HIGH] CVE-2007-0165: Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.
nvd
CVE-2007-0634P3HIGHCVSS 7.8PoCv10.02007-01-31
CVE-2007-0634 [HIGH] CVE-2007-0634: Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denia Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.
nvd
CVE-1999-0875P4HIGHCVSS 7.5PoCv2.61999-08-11
CVE-1999-0875 [HIGH] CWE-16 CVE-1999-0875: DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify the DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
nvd
CVE-2008-3869P3CRITICALCVSS 10.0v8.0v9.02009-05-26
CVE-2008-3869 [CRITICAL] CWE-119 CVE-2008-3869: Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbi Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters.
nvd
CVE-2003-0609P4HIGHCVSS 7.2PoCv2.6v7.0+2 more2003-08-27
CVE-2003-0609 [HIGH] CVE-2003-0609: Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local us Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.
nvd
CVE-1999-0493P4HIGHCVSS 7.5PoCv2.4v2.5+2 more1999-06-07
CVE-1999-0493 [HIGH] CVE-1999-0493: rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
nvd
CVE-2004-0791P4MEDIUMCVSS 5.0PoCv9.0v10.02005-04-12
CVE-2004-0791 [MEDIUM] CVE-2004-0791: Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (networ Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2
nvd
CVE-2002-0679P3CRITICALCVSS 10.0v2.6v9.02002-09-05
CVE-2002-0679 [CRITICAL] CVE-2002-0679: Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) a Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
nvd
CVE-2008-5689P4HIGHCVSS 7.2PoCv10.02008-12-19
CVE-2008-5689 [HIGH] CWE-399 CVE-2008-5689: tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a d tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.
nvd
CVE-2008-0965P3CRITICALCVSS 9.3v8v9+1 more2008-08-08
CVE-2008-0965 [CRITICAL] CWE-134 CVE-2008-0965: Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before s Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.
nvd
Sun Solaris vulnerabilities | cvebase