Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 6 of 22
CVE-2001-0353P3CRITICALCVSS 10.0v2.6v7.0+1 more2001-07-21
CVE-2001-0353 [CRITICAL] CVE-2001-0353: Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remot
Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
nvd
CVE-1999-0848P4MEDIUMCVSS 5.0PoCv7.01999-11-10
CVE-1999-0848 [MEDIUM] CVE-1999-0848: Denial of service in BIND named via consuming more than "fdmax" file descriptors.
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
nvd
CVE-1999-0241P3CRITICALCVSS 10.0v2.5v2.5.1+1 more1995-11-01
CVE-1999-0241 [CRITICAL] CVE-1999-0241: Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
nvd
CVE-2002-0084P4HIGHCVSS 7.2v2.6v8.02002-03-15
CVE-2002-0084 [HIGH] CVE-2002-0084: Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local user
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.
nvd
CVE-2004-1307P3HIGHCVSS 7.5v7.0v8.0+2 more2004-12-21
CVE-2004-1307 [HIGH] CVE-2004-1307: Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remot
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
nvd
CVE-2001-0548P4MEDIUMCVSS 4.6PoCv2.62001-08-14
CVE-2001-0548 [MEDIUM] CVE-2001-0548: Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL en
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
nvd
CVE-1999-0099P3CRITICALCVSS 10.0v2.41995-10-19
CVE-1999-0099 [CRITICAL] CVE-1999-0099: Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
nvd
CVE-2009-3839P3MEDIUMCVSS 6.8v10v10.02009-11-02
CVE-2009-3839 [MEDIUM] CVE-2009-3839: Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10,
Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10, and OpenSolaris snv_37 through snv_125, might allow remote attackers to execute arbitrary code by leveraging access to the X server.
nvd
CVE-1999-0908P4MEDIUMCVSS 5.0PoCv2.5.1v2.6+1 more1999-09-23
CVE-1999-0908 [MEDIUM] CVE-1999-0908: Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
nvd
CVE-2006-3824P4MEDIUMCVSS 4.9PoCv10.02006-07-25
CVE-2006-3824 [MEDIUM] CVE-2006-3824: systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argumen
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.
nvd
CVE-2010-0453P4MEDIUMCVSS 4.9PoCv10.02010-02-03
CVE-2010-0453 [MEDIUM] CWE-20 CVE-2010-0453: The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through sn
The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrie
nvd
CVE-2009-1478P4MEDIUMCVSS 4.9PoCv102009-04-29
CVE-2009-1478 [MEDIUM] CVE-2009-1478: Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris
Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.
nvd
CVE-2001-0565P4MEDIUMCVSS 4.6PoCv2.5v2.5.1+3 more2001-08-14
CVE-2001-0565 [MEDIUM] CVE-2001-0565: Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privile
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
nvd
CVE-2003-1073P4LOWCVSS 1.2PoCv2.6v7.0+2 more2003-12-31
CVE-2003-1073 [LOW] CVE-2003-1073: A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.
nvd
CVE-2004-1082P4HIGHCVSS 7.5v8.0v9.02004-02-03
CVE-2004-1082 [HIGH] CVE-2004-1082: mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
nvd
CVE-2002-0677P3HIGHCVSS 7.5v2.62002-07-23
CVE-2002-0677 [HIGH] CVE-2002-0677: CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory loca
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
nvd
CVE-2006-5726P4MEDIUMCVSS 4.9PoCv10.02006-11-06
CVE-2006-5726 [MEDIUM] CVE-2006-5726: alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memo
alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.
nvd
CVE-2001-0594P4MEDIUMCVSS 4.6PoCv7.0v8.02001-08-02
CVE-2001-0594 [MEDIUM] CVE-2001-0594: kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privilege
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.
nvd
CVE-2001-0526P4MEDIUMCVSS 4.6PoCv8.02001-08-14
CVE-2001-0526 [MEDIUM] CVE-2001-0526: Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local att
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.
nvd
CVE-1999-1014P4MEDIUMCVSS 4.6PoCv7.01999-09-13
CVE-1999-1014 [MEDIUM] CVE-1999-1014: Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a l
Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
nvd