Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 5 of 22
CVE-2001-0165P4HIGHCVSS 7.2PoCv7.0v8.02001-05-03
CVE-2001-0165 [HIGH] CVE-2001-0165: Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privi
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
nvd
CVE-2000-0118P4HIGHCVSS 7.2PoCv1.1.3v1.1.4+1 more1999-06-09
CVE-2000-0118 [HIGH] CVE-2000-0118: The Red Hat Linux su program does not log failed password guesses if the su process is killed before
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
nvd
CVE-2003-0196P3CRITICALCVSS 10.0v2.5.1v2.6+3 more2003-05-05
CVE-2003-0196 [CRITICAL] CVE-2003-0196: Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary cod
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
nvd
CVE-2008-1480P4MEDIUMCVSS 4.3PoCv102008-03-24
CVE-2008-1480 [MEDIUM] CVE-2008-1480: rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.
nvd
CVE-2002-0572P4HIGHCVSS 7.2PoCv2.5.1v2.6+2 more2002-07-03
CVE-2002-0572 [HIGH] CVE-2002-0572: FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
nvd
CVE-2001-1076P4HIGHCVSS 7.2PoCv2.5v2.5.1+3 more2001-07-05
CVE-2001-1076 [HIGH] CVE-2001-1076: Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
nvd
CVE-1999-0051P4HIGHCVSS 7.2PoCv2.4v2.5+1 more1997-01-06
CVE-1999-0051 [HIGH] CVE-1999-0051: Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0,
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
nvd
CVE-2002-0797P3CRITICALCVSS 10.0v2.6v7.0+1 more2002-08-12
CVE-2002-0797 [CRITICAL] CVE-2002-0797: Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote atta
Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
nvd
CVE-2002-1584P3CRITICALCVSS 10.0v2.5.1v2.6+1 more2002-12-27
CVE-2002-1584 [CRITICAL] CVE-2002-1584: Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX
Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.
nvd
CVE-2001-0423P4HIGHCVSS 7.2PoCv7.02001-07-02
CVE-2001-0423 [HIGH] CVE-2001-0423: Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.
nvd
CVE-1999-0767P4HIGHCVSS 7.2PoCv2.6v7.01999-09-08
CVE-1999-0767 [HIGH] CVE-1999-0767: Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
nvd
CVE-2005-2071P4MEDIUMCVSS 4.6PoCv10.02005-06-29
CVE-2005-2071 [MEDIUM] CWE-264 CVE-2005-2071: traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_N
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).
nvd
CVE-2002-0796P3CRITICALCVSS 10.0v2.6v7.0+1 more2002-08-12
CVE-2002-0796 [CRITICAL] CVE-2002-0796: Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remo
Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
nvd
CVE-1999-0186P3CRITICALCVSS 10.0v2.61998-10-01
CVE-1999-0186 [CRITICAL] CVE-1999-0186: In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
nvd
CVE-1999-0974P3CRITICALCVSS 10.0v2.4v2.5+3 more1999-12-09
CVE-1999-0974 [CRITICAL] CVE-1999-0974: Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA reques
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
nvd
CVE-2002-0573P3HIGHCVSS 7.5v2.6v7.0+1 more2002-07-03
CVE-2002-0573 [HIGH] CVE-2002-0573: Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remot
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
nvd
CVE-2003-0028P3HIGHCVSS 7.5v2.5.1v2.6+3 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-1999-0674P4HIGHCVSS 7.2PoCv2.4v2.5+2 more1999-08-09
CVE-1999-0674 [HIGH] CVE-1999-0674: The BSD profil system call allows a local user to modify the internal data space of a program via pr
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
nvd
CVE-1999-0818P4HIGHCVSS 7.2PoCv7.01999-11-20
CVE-1999-0818 [HIGH] CVE-1999-0818: Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
nvd
CVE-2006-4655P4MEDIUMCVSS 4.6PoCv8.0v9.0+1 more2006-09-09
CVE-2006-4655 [MEDIUM] CVE-2006-4655: Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and ear
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.
nvd