Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 3 of 22
CVE-2008-3870P3CRITICALCVSS 10.0v8.0v9.02009-05-26
CVE-2008-3870 [CRITICAL] CWE-189 CVE-2008-3870: Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code
Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation.
nvd
CVE-2009-2296P3CRITICALCVSS 10.0v102009-07-02
CVE-2009-2296 [CRITICAL] CVE-2009-2296: The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly
The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create, and modify arbitrary files, via unspecified vectors.
nvd
CVE-2007-6413P3CRITICALCVSS 9.3v102007-12-17
CVE-2007-6413 [CRITICAL] CWE-264 CVE-2007-6413: Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, al
Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup restrictions and obtain root access to a filesystem via NFS requests from a client root user.
nvd
CVE-2006-0745P4HIGHCVSS 7.2PoCv10.02006-03-21
CVE-2006-0745 [HIGH] CVE-2006-0745: X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
nvd
CVE-2008-4131P4HIGHCVSS 7.2PoCv8v9+1 more2008-09-19
CVE-2008-4131 [HIGH] CWE-264 CVE-2008-4131: Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privilege
Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.
nvd
CVE-2000-0032P4CRITICALCVSS 10.0PoCv7.01999-12-22
CVE-2000-0032 [CRITICAL] CVE-2000-0032: Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var
Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.
nvd
CVE-1999-1191P4HIGHCVSS 7.2PoCv2.4v2.5+1 more1997-05-19
CVE-1999-1191 [HIGH] CVE-1999-1191: Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
nvd
CVE-2004-0523P3CRITICALCVSS 10.0v8.0v9.02004-08-18
CVE-2004-0523 [CRITICAL] CVE-2004-0523: Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier all
Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
nvd
CVE-2005-3398P4MEDIUMCVSS 4.3PoCv9.0v10.02005-11-01
CVE-2005-3398 [MEDIUM] CWE-200 CVE-2005-3398: The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.
nvd
CVE-1999-1432P4HIGHCVSS 7.5PoCv2.4v2.5+2 more1998-07-16
CVE-1999-1432 [HIGH] CVE-1999-1432: Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
nvd
CVE-2000-0471P4HIGHCVSS 7.2PoCv1.1.3v1.1.4+9 more2000-06-14
CVE-2000-0471 [HIGH] CVE-2000-0471: Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges vi
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
nvd
CVE-2001-0115P4HIGHCVSS 7.2PoCv2.4v2.5+3 more2001-03-12
CVE-2001-0115 [HIGH] CVE-2001-0115: Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary comm
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
nvd
CVE-2002-0158P4HIGHCVSS 7.2PoCv2.6v7.0+1 more2002-04-02
CVE-2002-0158 [HIGH] CVE-2002-0158: Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a lo
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.
nvd
CVE-2005-2072P4HIGHCVSS 7.2PoCv8.0v9.0+1 more2005-06-29
CVE-2005-2072 [HIGH] CWE-264 CVE-2005-2072: The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setui
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
nvd
CVE-2007-3093P3CRITICALCVSS 10.0v8.0v9.0+1 more2007-06-06
CVE-2007-3093 [CRITICAL] CVE-2007-3093: Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solari
Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.
nvd
CVE-2001-0421P4MEDIUMCVSS 6.4PoCv2.62001-07-02
CVE-2001-0421 [MEDIUM] CVE-2001-0421: FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the ro
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
nvd
CVE-2001-0422P4HIGHCVSS 7.2PoCv2.62001-07-02
CVE-2001-0422 [HIGH] CVE-2001-0422: Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands vi
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2000-0317P4HIGHCVSS 7.2PoCv2.6v7.02000-04-24
CVE-2000-0317 [HIGH] CVE-2000-0317: Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
nvd
CVE-2004-2686P4HIGHCVSS 7.2PoCv2.6v7.0+2 more2004-12-31
CVE-2004-2686 [HIGH] CVE-2004-2686: Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows lo
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.
nvd
CVE-2001-0426P4HIGHCVSS 7.2PoCv2.6v7.0+1 more2001-07-02
CVE-2001-0426 [HIGH] CVE-2001-0426: Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
nvd