Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 11 of 27
CVE-2009-4191P4HIGHCVSS 7.2v5.102009-12-03
CVE-2009-4191 [HIGH] CVE-2009-4191: Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 plat
Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated by the vd_sol_local module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a re
nvd
CVE-2012-3127P4MEDIUMCVSS 5.4v5.102012-07-17
CVE-2012-3127 [MEDIUM] CVE-2012-3127: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, r
Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to SCTP.
nvd
CVE-2012-3121P4MEDIUMCVSS 5.0v5.9v5.102012-07-17
CVE-2012-3121 [MEDIUM] CVE-2012-3121: Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availabil
Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availability via unknown vectors related to in.tnamed and NameServer.
nvd
CVE-2011-0820P4MEDIUMCVSS 5.4v5.10v5.112011-04-20
CVE-2011-0820 [MEDIUM] CVE-2011-0820: Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows remote attackers to affect ava
Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Kernel.
nvd
CVE-2012-3123P4MEDIUMCVSS 5.0v5.102012-07-17
CVE-2012-3123 [MEDIUM] CVE-2012-3123: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality
Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.
nvd
CVE-2010-4433P4MEDIUMCVSS 5.0v5.102011-01-19
CVE-2010-4433 [MEDIUM] CVE-2010-4433: Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via
Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via unknown vectors related to Ethernet and the Driver sub-component.
nvd
CVE-2011-2294P4MEDIUMCVSS 5.0v5.10v5.112011-07-21
CVE-2011-2294 [MEDIUM] CVE-2011-2294: Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect avai
Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to SSH.
nvd
CVE-2011-2298P4MEDIUMCVSS 5.0v5.10v5.112011-07-21
CVE-2011-2298 [MEDIUM] CVE-2011-2298: Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect avai
Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to KSSL.
nvd
CVE-2014-6575P4MEDIUMCVSS 5.0v5.10v5.112015-01-21
CVE-2014-6575 [MEDIUM] CVE-2014-6575: Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availabi
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE-2004-0230.
nvd
CVE-2003-1078P4HIGHCVSS 7.5v5.7v5.82003-02-28
CVE-2003-1078 [HIGH] CVE-2003-1078: The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
nvd
CVE-2014-6473P4HIGHCVSS 7.2v5.10v5.112014-10-15
CVE-2014-6473 [HIGH] CVE-2014-6473: Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiali
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Framework.
nvd
CVE-1999-0190P4HIGHCVSS 7.2v5.3v5.4+2 more1998-04-08
CVE-1999-0190 [HIGH] CVE-1999-0190: Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
nvd
CVE-1999-0837P4CRITICALCVSS 10.0v5.71999-11-10
CVE-1999-0837 [CRITICAL] CVE-1999-0837: Denial of service in BIND by improperly closing TCP sessions via so_linger.
Denial of service in BIND by improperly closing TCP sessions via so_linger.
nvd
CVE-2006-7140P4MEDIUMCVSS 5.8v5.92007-03-07
CVE-2006-7140 [MEDIUM] CVE-2006-7140: The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA
The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents libike from correctly verifying X.509 and other certificates that use PKCS #1, a s
nvd
CVE-1999-0213P4CRITICALCVSS 10.0v5.4v5.5+1 more1998-07-15
CVE-1999-0213 [CRITICAL] CVE-1999-0213: libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
nvd
CVE-1999-0017P4HIGHCVSS 7.5v4.1.3u1v4.1.4+4 more1997-12-10
CVE-1999-0017 [HIGH] CVE-1999-0017: FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP clien
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
nvd
CVE-1999-0835P4CRITICALCVSS 10.0v5.71999-11-10
CVE-1999-0835 [CRITICAL] CVE-1999-0835: Denial of service in BIND named via malformed SIG records.
Denial of service in BIND named via malformed SIG records.
nvd
CVE-2012-0096P4MEDIUMCVSS 5.0v5.8v5.9+2 more2012-01-18
CVE-2012-0096 [MEDIUM] CVE-2012-0096: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affe
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network.
nvd
CVE-1999-0022P4HIGHCVSS 7.8v4.1.1v4.1.2+6 more1996-07-03
CVE-1999-0022 [HIGH] CWE-125 CVE-1999-0022: Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
nvd
CVE-2008-3666P4HIGHCVSS 7.1v5.102008-08-13
CVE-2008-3666 [HIGH] CVE-2008-3666: Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-depende
Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a
nvd