Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 4 of 22
CVE-2000-0337P4HIGHCVSS 7.2PoCv7.0v8.02000-04-24
CVE-2000-0337 [HIGH] CVE-2000-0337: Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long
Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
nvd
CVE-1999-0315P4HIGHCVSS 7.2PoCv2.4v2.5+2 more1997-04-01
CVE-1999-0315 [HIGH] CVE-1999-0315: Buffer overflow in Solaris fdformat command gives root access to local users.
Buffer overflow in Solaris fdformat command gives root access to local users.
nvd
CVE-1999-0691P4HIGHCVSS 7.2PoCv2.4v2.5.1+2 more1999-09-13
CVE-1999-0691 [HIGH] CVE-1999-0691: Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
nvd
CVE-1999-0369P4HIGHCVSS 7.2PoCv1.1.3v1.1.4+2 more1997-02-01
CVE-1999-0369 [HIGH] CVE-1999-0369: The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root acc
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
nvd
CVE-1999-0948P4HIGHCVSS 7.2PoCv2.6v7.01999-11-02
CVE-1999-0948 [HIGH] CVE-1999-0948: Buffer overflow in uum program for Canna input system allows local users to gain root privileges.
Buffer overflow in uum program for Canna input system allows local users to gain root privileges.
nvd
CVE-1999-0949P4HIGHCVSS 7.2PoCv2.6v7.01999-11-02
CVE-1999-0949 [HIGH] CVE-1999-0949: Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.
nvd
CVE-2007-3094P3CRITICALCVSS 9.0v8.0v9.0+1 more2007-06-06
CVE-2007-3094 [CRITICAL] CVE-2007-3094: Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun
Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to execute arbitrary code via unspecified vectors, related to the WBEM server.
nvd
CVE-1999-0040P4HIGHCVSS 7.2PoCv2.4v2.5+1 more1997-05-01
CVE-1999-0040 [HIGH] CVE-1999-0040: Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
nvd
CVE-2003-1055P4HIGHCVSS 7.2PoCv8.0v9.02003-07-03
CVE-2003-1055 [HIGH] CVE-2003-1055: Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain r
Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.
nvd
CVE-2001-0401P4HIGHCVSS 7.2PoCv2.62001-06-18
CVE-2001-0401 [HIGH] CVE-2001-0401: Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2004-0360P4HIGHCVSS 7.2PoCv8.0v9.02004-11-23
CVE-2004-0360 [HIGH] CVE-2004-0360: Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via
Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.
nvd
CVE-2000-0316P4HIGHCVSS 7.2PoCv7.02000-04-24
CVE-2000-0316 [HIGH] CVE-2000-0316: Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
nvd
CVE-1999-1026P4HIGHCVSS 7.2PoCv2.4v2.5+1 more1996-12-20
CVE-1999-1026 [HIGH] CVE-1999-1026: aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
nvd
CVE-1999-0689P4HIGHCVSS 7.2PoCv2.5v2.5.1+2 more1999-09-13
CVE-1999-0689 [HIGH] CVE-1999-0689: The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
nvd
CVE-1999-0773P4HIGHCVSS 7.2PoCv2.6v7.01999-05-11
CVE-1999-0773 [HIGH] CVE-1999-0773: Buffer overflow in Solaris lpset program allows local users to gain root access.
Buffer overflow in Solaris lpset program allows local users to gain root access.
nvd
CVE-1999-0038P4HIGHCVSS 8.4PoCv2.4v2.5+1 more1997-04-26
CVE-1999-0038 [HIGH] CWE-120 CVE-1999-0038: Buffer overflow in xlock program allows local users to execute commands as root.
Buffer overflow in xlock program allows local users to execute commands as root.
nvd
CVE-2000-0407P4HIGHCVSS 7.2PoCv2.6v7.0+1 more2000-05-12
CVE-2000-0407 [HIGH] CVE-2000-0407: Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
nvd
CVE-2006-4842P4LOWCVSS 3.6PoCv10.02006-10-12
CVE-2006-4842 [LOW] CWE-20 CVE-2006-4842: The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-spe
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
nvd
CVE-2004-1351P3CRITICALCVSS 10.0v7.0v8.0+1 more2004-12-07
CVE-2004-1351 [CRITICAL] CVE-2004-1351: Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers
Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.
nvd
CVE-2001-1582P4HIGHCVSS 7.2PoCv8.02001-12-31
CVE-2001-1582 [HIGH] CWE-119 CVE-2001-1582: Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users t
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
nvd