Sun Solaris vulnerabilities
429 known vulnerabilities affecting sun/solaris.
Total CVEs
429
CISA KEV
0
Public exploits
98
Exploited in wild
0
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55
Vulnerabilities
Page 7 of 22
CVE-2007-4732MEDIUMCVSS 4.9v8.0v9.0+1 more2007-09-06
CVE-2007-4732 [MEDIUM] CWE-20 CVE-2007-4732: Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Sol
Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.
nvd
CVE-2007-4495MEDIUMCVSS 4.9v8.0v9.0+1 more2007-08-23
CVE-2007-4495 [MEDIUM] CVE-2007-4495: Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 200708
Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 20070821 allows local users to cause a denial of service (system panic) via an unspecified ioctl function, aka Bug 6433124.
nvd
CVE-2007-4492MEDIUMCVSS 4.9v8.0v9.0+1 more2007-08-23
CVE-2007-4492 [MEDIUM] CVE-2007-4492: Multiple unspecified vulnerabilities in the ata disk driver in Sun Solaris 8, 9, and 10 on the x86 p
Multiple unspecified vulnerabilities in the ata disk driver in Sun Solaris 8, 9, and 10 on the x86 platform before 20070821 allow local users to cause a denial of service (system panic) via unspecified ioctl functions, aka Bug 6433123.
nvd
CVE-2007-4126LOWCVSS 1.5v10.02007-08-01
CVE-2007-4126 [LOW] CVE-2007-4126: Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 2007073
Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.
nvd
CVE-2007-4070MEDIUMCVSS 4.9v8.0v9.0+1 more2007-07-30
CVE-2007-4070 [MEDIUM] CVE-2007-4070: Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 200
Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.
nvd
CVE-2007-3471HIGHCVSS 7.2v8.0v9.0+1 more2007-06-28
CVE-2007-3471 [HIGH] CVE-2007-3471: Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8,
Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.
nvd
CVE-2007-3470HIGHCVSS 7.8v10.02007-06-28
CVE-2007-3470 [HIGH] CVE-2007-3470: Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured wi
Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records.
nvd
CVE-2007-3469MEDIUMCVSS 4.9v10.02007-06-28
CVE-2007-3469 [MEDIUM] CVE-2007-3469: Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local u
Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.
nvd
CVE-2007-3458MEDIUMCVSS 4.9v8.0v9.0+1 more2007-06-27
CVE-2007-3458 [MEDIUM] CVE-2007-3458: The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Na
The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Name Service Caching Daemon (nscd) crash) via unspecified vectors.
nvd
CVE-2007-3283MEDIUMCVSS 6.8v8.0v9.02007-06-19
CVE-2007-3283 [MEDIUM] CVE-2007-3283: GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, doe
GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.
nvd
CVE-2007-3248HIGHCVSS 7.8v10.02007-06-18
CVE-2007-3248 [HIGH] CVE-2007-3248: Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but no
Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (system crash) via certain network traffic.
nvd
CVE-2007-3223HIGHCVSS 7.8v10.02007-06-14
CVE-2007-3223 [HIGH] CVE-2007-3223: Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attacker
Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.
nvd
CVE-2007-3093CRITICALCVSS 10.0v8.0v9.0+1 more2007-06-06
CVE-2007-3093 [CRITICAL] CVE-2007-3093: Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solari
Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.
nvd
CVE-2007-3094CRITICALCVSS 9.0v8.0v9.0+1 more2007-06-06
CVE-2007-3094 [CRITICAL] CVE-2007-3094: Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun
Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to execute arbitrary code via unspecified vectors, related to the WBEM server.
nvd
CVE-2007-3069MEDIUMCVSS 4.6v10.02007-06-06
CVE-2007-3069 [MEDIUM] CVE-2007-3069: xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology suppo
xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.
nvd
CVE-2007-2989HIGHCVSS 7.8v9.02007-06-01
CVE-2007-2989 [HIGH] CVE-2007-2989: The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain poin
The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain pointer, which allows remote attackers to cause a denial of service (in.iked daemon crash) by sending certain UDP packets with a source port different from 500. NOTE: this issue might overlap CVE-2006-2298.
nvd
CVE-2007-2990MEDIUMCVSS 4.9v10.02007-06-01
CVE-2007-2990 [MEDIUM] CVE-2007-2990: Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a d
Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.
nvd
CVE-2007-2882MEDIUMCVSS 5.0v8.0v9.0+1 more2007-05-30
CVE-2007-2882 [MEDIUM] CVE-2007-2882: Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when
Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.
nvd
CVE-2007-2529HIGHCVSS 7.2v10.02007-05-09
CVE-2007-2529 [HIGH] CVE-2007-2529: Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local us
Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.
nvd
CVE-2007-2465MEDIUMCVSS 4.7v9.02007-05-02
CVE-2007-2465 [MEDIUM] CVE-2007-2465: Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, wr
Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.
nvd