cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 11 of 27
CVE-2009-4191P4HIGHCVSS 7.2v5.102009-12-03
CVE-2009-4191 [HIGH] CVE-2009-4191: Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 plat Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated by the vd_sol_local module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a re
nvd
CVE-2012-3127P4MEDIUMCVSS 5.4v5.102012-07-17
CVE-2012-3127 [MEDIUM] CVE-2012-3127: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, r Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to SCTP.
nvd
CVE-2012-3121P4MEDIUMCVSS 5.0v5.9v5.102012-07-17
CVE-2012-3121 [MEDIUM] CVE-2012-3121: Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availabil Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availability via unknown vectors related to in.tnamed and NameServer.
nvd
CVE-2011-0820P4MEDIUMCVSS 5.4v5.10v5.112011-04-20
CVE-2011-0820 [MEDIUM] CVE-2011-0820: Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows remote attackers to affect ava Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Kernel.
nvd
CVE-2012-3123P4MEDIUMCVSS 5.0v5.102012-07-17
CVE-2012-3123 [MEDIUM] CVE-2012-3123: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
nvd
CVE-2010-4433P4MEDIUMCVSS 5.0v5.102011-01-19
CVE-2010-4433 [MEDIUM] CVE-2010-4433: Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via unknown vectors related to Ethernet and the Driver sub-component.
nvd
CVE-2011-2294P4MEDIUMCVSS 5.0v5.10v5.112011-07-21
CVE-2011-2294 [MEDIUM] CVE-2011-2294: Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect avai Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to SSH.
nvd
CVE-2011-2298P4MEDIUMCVSS 5.0v5.10v5.112011-07-21
CVE-2011-2298 [MEDIUM] CVE-2011-2298: Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect avai Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to KSSL.
nvd
CVE-2014-6575P4MEDIUMCVSS 5.0v5.10v5.112015-01-21
CVE-2014-6575 [MEDIUM] CVE-2014-6575: Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availabi Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE-2004-0230.
nvd
CVE-2003-1078P4HIGHCVSS 7.5v5.7v5.82003-02-28
CVE-2003-1078 [HIGH] CVE-2003-1078: The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
nvd
CVE-2014-6473P4HIGHCVSS 7.2v5.10v5.112014-10-15
CVE-2014-6473 [HIGH] CVE-2014-6473: Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiali Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Framework.
nvd
CVE-1999-0190P4HIGHCVSS 7.2v5.3v5.4+2 more1998-04-08
CVE-1999-0190 [HIGH] CVE-1999-0190: Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
nvd
CVE-1999-0837P4CRITICALCVSS 10.0v5.71999-11-10
CVE-1999-0837 [CRITICAL] CVE-1999-0837: Denial of service in BIND by improperly closing TCP sessions via so_linger. Denial of service in BIND by improperly closing TCP sessions via so_linger.
nvd
CVE-2006-7140P4MEDIUMCVSS 5.8v5.92007-03-07
CVE-2006-7140 [MEDIUM] CVE-2006-7140: The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents libike from correctly verifying X.509 and other certificates that use PKCS #1, a s
nvd
CVE-1999-0213P4CRITICALCVSS 10.0v5.4v5.5+1 more1998-07-15
CVE-1999-0213 [CRITICAL] CVE-1999-0213: libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind. libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
nvd
CVE-1999-0017P4HIGHCVSS 7.5v4.1.3u1v4.1.4+4 more1997-12-10
CVE-1999-0017 [HIGH] CVE-1999-0017: FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP clien FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
nvd
CVE-1999-0835P4CRITICALCVSS 10.0v5.71999-11-10
CVE-1999-0835 [CRITICAL] CVE-1999-0835: Denial of service in BIND named via malformed SIG records. Denial of service in BIND named via malformed SIG records.
nvd
CVE-2012-0096P4MEDIUMCVSS 5.0v5.8v5.9+2 more2012-01-18
CVE-2012-0096 [MEDIUM] CVE-2012-0096: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affe Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network.
nvd
CVE-1999-0022P4HIGHCVSS 7.8v4.1.1v4.1.2+6 more1996-07-03
CVE-1999-0022 [HIGH] CWE-125 CVE-1999-0022: Local user gains root privileges via buffer overflow in rdist, via expstr() function. Local user gains root privileges via buffer overflow in rdist, via expstr() function.
nvd
CVE-2008-3666P4HIGHCVSS 7.1v5.102008-08-13
CVE-2008-3666 [HIGH] CVE-2008-3666: Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-depende Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a
nvd
Sun Sunos vulnerabilities | cvebase