cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 7 of 22
CVE-1999-0097P4CRITICALCVSS 10.0v2.4v2.5+2 more1997-10-29
CVE-1999-0097 [CRITICAL] CVE-1999-0097: The AIX FTP client can be forced to execute commands from a malicious server through shell metachara The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
nvd
CVE-2009-0872P4MEDIUMCVSS 6.8v102009-03-11
CVE-2009-0872 [MEDIUM] CWE-264 CVE-2009-0872: The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AU The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.
nvd
CVE-2009-0873P4MEDIUMCVSS 6.8v10.02009-03-11
CVE-2009-0873 [MEDIUM] CWE-264 CVE-2009-0873: The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "ov
nvd
CVE-1999-1587P4LOWCVSS 2.1PoCv9.01999-12-31
CVE-1999-1587 [LOW] CVE-1999-1587: /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.
nvd
CVE-1999-0786P4MEDIUMCVSS 4.6PoCv2.4v2.5+2 more1999-09-22
CVE-1999-0786 [MEDIUM] CVE-1999-0786: The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE envir The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
nvd
CVE-2005-2870P4HIGHCVSS 7.5v10.02005-09-08
CVE-2005-2870 [HIGH] CVE-2005-2870: Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execu Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
nvd
CVE-2003-1071P4LOWCVSS 2.1PoCv2.5.1v2.6+3 more2003-01-03
CVE-2003-1071 [LOW] CVE-2003-1071: rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on u rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
nvd
CVE-2009-0923P4HIGHCVSS 7.8v10.02009-03-17
CVE-2009-0923 [HIGH] CVE-2009-0923: Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 t Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.
nvd
CVE-1999-0185P4HIGHCVSS 7.5v2.4v2.5+1 more1997-10-01
CVE-1999-0185 [HIGH] CVE-1999-0185: In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
nvd
CVE-2007-1681P4HIGHCVSS 7.5v10.02007-04-19
CVE-2007-1681 [HIGH] CVE-2007-1681: Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.
nvd
CVE-1999-1413P4MEDIUMCVSS 4.6PoCv2.41996-08-03
CVE-1999-1413 [MEDIUM] CVE-1999-1413: Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
nvd
CVE-1999-1402P4LOWCVSS 2.1PoCv2.5v2.5.1+1 more1997-05-17
CVE-1999-1402 [LOW] CVE-1999-1402: The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
nvd
CVE-2009-2487P4HIGHCVSS 7.8v102009-07-16
CVE-2009-2487 [HIGH] CWE-399 CVE-2009-2487: Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.
nvd
CVE-2007-3223P4HIGHCVSS 7.8v10.02007-06-14
CVE-2007-3223 [HIGH] CVE-2007-3223: Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attacker Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.
nvd
CVE-2009-2136P4HIGHCVSS 7.8v10.02009-06-19
CVE-2009-2136 [HIGH] CVE-2009-2136: Unspecified vulnerability in the TCP/IP networking stack in Sun Solaris 10, and OpenSolaris snv_01 t Unspecified vulnerability in the TCP/IP networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_117, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames.
nvd
CVE-2008-2090P4HIGHCVSS 7.8v102008-05-06
CVE-2008-2090 [HIGH] CWE-399 CVE-2008-2090: Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attack Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.
nvd
CVE-2005-0248P4HIGHCVSS 7.5v8.0v9.02005-05-02
CVE-2005-0248 [HIGH] CVE-2005-0248: The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are c The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
nvd
CVE-2008-2710P4HIGHCVSS 7.2≤ 102008-06-16
CVE-2008-2710 [HIGH] CWE-189 CVE-2008-2710: Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/i Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an o
nvd
CVE-2009-3899P4HIGHCVSS 7.8v102009-11-06
CVE-2009-3899 [HIGH] CWE-399 CVE-2009-3899: Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 th Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 through snv_94, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvd
CVE-2009-2972P4HIGHCVSS 7.8v8v92009-08-27
CVE-2009-2972 [HIGH] CWE-399 CVE-2009-2972: in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of serv in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."
nvd