cbcvebase.

Sun Solaris vulnerabilities

429 known vulnerabilities affecting sun/solaris.

Total CVEs
429
CISA KEV
0
Public exploits
102
Exploited in wild
6
Severity breakdown
CRITICAL49HIGH153MEDIUM172LOW55

Vulnerabilities

Page 9 of 22
CVE-2009-3468P4MEDIUMCVSS 6.9v10.02009-09-29
CVE-2009-3468 [MEDIUM] CVE-2009-3468: Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Tru Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager.
nvd
CVE-2007-2989P4HIGHCVSS 7.8v9.02007-06-01
CVE-2007-2989 [HIGH] CVE-2007-2989: The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain poin The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain pointer, which allows remote attackers to cause a denial of service (in.iked daemon crash) by sending certain UDP packets with a source port different from 500. NOTE: this issue might overlap CVE-2006-2298.
nvd
CVE-2007-3470P4HIGHCVSS 7.8v10.02007-06-28
CVE-2007-3470 [HIGH] CVE-2007-3470: Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured wi Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records.
nvd
CVE-2006-5075P4HIGHCVSS 7.8v10.02006-09-29
CVE-2006-5075 [HIGH] CVE-2006-5075: The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remot The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client.
nvd
CVE-2003-1081P4CRITICALCVSS 10.0v8.02003-09-09
CVE-2003-1081 [CRITICAL] CWE-264 CVE-2003-1081: Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .a Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.
nvd
CVE-2009-2137P4HIGHCVSS 7.8v102009-06-19
CVE-2009-2137 [HIGH] CWE-399 CVE-2009-2137: Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and Op Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-dependent attackers to cause a denial of service (memory consumption) via unspecified vectors related to a large keylen value.
nvd
CVE-1999-0302P4HIGHCVSS 7.5v2.61998-09-01
CVE-1999-0302 [HIGH] CVE-1999-0302: SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server. SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
nvd
CVE-2009-3000P4HIGHCVSS 7.1v10.02009-08-28
CVE-2009-3000 [HIGH] CWE-399 CVE-2009-3000: The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Netwo The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handl
nvd
CVE-1999-0320P4CRITICALCVSS 9.3v2.4v2.5+1 more1998-03-01
CVE-1999-0320 [CRITICAL] CVE-1999-0320: SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files. SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
nvd
CVE-2009-3183P4HIGHCVSS 7.2v8v9+1 more2009-09-14
CVE-2009-3183 [HIGH] CWE-119 CVE-2009-3183: Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows local users to gain privileges via unspecified vectors.
nvd
CVE-1999-0859P4LOWCVSS 2.1PoCv2.5.1v2.6+1 more1999-12-01
CVE-1999-0859 [LOW] CVE-1999-0859: Solaris arp allows local users to read files via the -f parameter, which lists lines in the file tha Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
nvd
CVE-2007-5716P4HIGHCVSS 7.8v10.02007-10-30
CVE-2007-5716 [HIGH] CVE-2007-5716: Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.
nvd
CVE-2006-7028P4HIGHCVSS 7.8v9.02007-02-23
CVE-2006-7028 [HIGH] CVE-2006-7028: Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a denial of service (console hang) via a flood of small TCP/IP packets. NOTE: this issue has not been replicated by third parties. In addition, the cause is unknown, although it might be related to "jabber" and generation of a large amount of interrupts within the
nvd
CVE-2003-1063P4HIGHCVSS 7.5v2.6v7.02003-08-20
CVE-2003-1063 [HIGH] CVE-2003-1063: The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2. The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
nvd
CVE-2007-3471P4HIGHCVSS 7.2v8.0v9.0+1 more2007-06-28
CVE-2007-3471 [HIGH] CVE-2007-3471: Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.
nvd
CVE-2005-3674P4HIGHCVSS 7.8v9.0v10.02005-11-18
CVE-2005-3674 [HIGH] CVE-2005-3674: The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 an The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked crash) via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-
nvd
CVE-2006-3781P4HIGHCVSS 7.8v10.02006-07-24
CVE-2006-3781 [HIGH] CVE-2006-3781: Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via unspecified vectors involving the event port API.
nvd
CVE-2009-3164P4HIGHCVSS 7.1v10.02009-09-10
CVE-2009-3164 [HIGH] CVE-2009-3164: Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 thr Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix fo
nvd
CVE-2008-1095P4MEDIUMCVSS 6.8v8v9+1 more2008-02-29
CVE-2008-1095 [MEDIUM] CWE-264 CVE-2008-1095: Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 a Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.
nvd
CVE-2006-4319P4HIGHCVSS 7.2v8.0v9.0+1 more2006-08-24
CVE-2006-4319 [HIGH] CVE-2006-4319: Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to form Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307.
nvd