cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 5 of 22
CVE-2001-0165P4HIGHCVSS 7.2PoCv7.0v8.02001-05-03
CVE-2001-0165 [HIGH] CVE-2001-0165: Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privi Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
nvd
CVE-2000-0118P4HIGHCVSS 7.2PoCv1.1.3v1.1.4+1 more1999-06-09
CVE-2000-0118 [HIGH] CVE-2000-0118: The Red Hat Linux su program does not log failed password guesses if the su process is killed before The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
nvd
CVE-2003-0196P3CRITICALCVSS 10.0v2.5.1v2.6+3 more2003-05-05
CVE-2003-0196 [CRITICAL] CVE-2003-0196: Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary cod Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
nvd
CVE-2008-1480P4MEDIUMCVSS 4.3PoCv102008-03-24
CVE-2008-1480 [MEDIUM] CVE-2008-1480: rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.
nvd
CVE-2002-0572P4HIGHCVSS 7.2PoCv2.5.1v2.6+2 more2002-07-03
CVE-2002-0572 [HIGH] CVE-2002-0572: FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
nvd
CVE-2001-1076P4HIGHCVSS 7.2PoCv2.5v2.5.1+3 more2001-07-05
CVE-2001-1076 [HIGH] CVE-2001-1076: Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
nvd
CVE-1999-0051P4HIGHCVSS 7.2PoCv2.4v2.5+1 more1997-01-06
CVE-1999-0051 [HIGH] CVE-1999-0051: Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
nvd
CVE-2002-0797P3CRITICALCVSS 10.0v2.6v7.0+1 more2002-08-12
CVE-2002-0797 [CRITICAL] CVE-2002-0797: Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote atta Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
nvd
CVE-2002-1584P3CRITICALCVSS 10.0v2.5.1v2.6+1 more2002-12-27
CVE-2002-1584 [CRITICAL] CVE-2002-1584: Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.
nvd
CVE-2001-0423P4HIGHCVSS 7.2PoCv7.02001-07-02
CVE-2001-0423 [HIGH] CVE-2001-0423: Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.
nvd
CVE-1999-0767P4HIGHCVSS 7.2PoCv2.6v7.01999-09-08
CVE-1999-0767 [HIGH] CVE-1999-0767: Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable. Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
nvd
CVE-2005-2071P4MEDIUMCVSS 4.6PoCv10.02005-06-29
CVE-2005-2071 [MEDIUM] CWE-264 CVE-2005-2071: traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_N traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).
nvd
CVE-2002-0796P3CRITICALCVSS 10.0v2.6v7.0+1 more2002-08-12
CVE-2002-0796 [CRITICAL] CVE-2002-0796: Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remo Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
nvd
CVE-1999-0186P3CRITICALCVSS 10.0v2.61998-10-01
CVE-1999-0186 [CRITICAL] CVE-1999-0186: In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
nvd
CVE-1999-0974P3CRITICALCVSS 10.0v2.4v2.5+3 more1999-12-09
CVE-1999-0974 [CRITICAL] CVE-1999-0974: Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA reques Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
nvd
CVE-2002-0573P3HIGHCVSS 7.5v2.6v7.0+1 more2002-07-03
CVE-2002-0573 [HIGH] CVE-2002-0573: Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remot Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
nvd
CVE-2003-0028P3HIGHCVSS 7.5v2.5.1v2.6+3 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-1999-0674P4HIGHCVSS 7.2PoCv2.4v2.5+2 more1999-08-09
CVE-1999-0674 [HIGH] CVE-1999-0674: The BSD profil system call allows a local user to modify the internal data space of a program via pr The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
nvd
CVE-1999-0818P4HIGHCVSS 7.2PoCv7.01999-11-20
CVE-1999-0818 [HIGH] CVE-1999-0818: Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
nvd
CVE-2006-4655P4MEDIUMCVSS 4.6PoCv8.0v9.0+1 more2006-09-09
CVE-2006-4655 [MEDIUM] CVE-2006-4655: Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and ear Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.
nvd
Sun Solaris vulnerabilities | cvebase