Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 14 of 27
CVE-1999-1211P4HIGHCVSS 7.2≤ 4.1.11991-03-27
CVE-1999-1211 [HIGH] CVE-1999-1211: Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.
Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.
nvd
CVE-1999-0952P4HIGHCVSS 7.2v5.71999-01-28
CVE-1999-0952 [HIGH] CVE-1999-0952: Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
nvd
CVE-2013-3837P4MEDIUMCVSS 4.3v5.102013-10-16
CVE-2013-3837 [MEDIUM] CVE-2013-3837: Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows remote attackers to affect availabili
Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows remote attackers to affect availability via unknown vectors related to Cacao.
nvd
CVE-2006-6494P4MEDIUMCVSS 6.6v5.82006-12-13
CVE-2006-6494 [MEDIUM] CVE-2006-6494: Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execu
Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.
nvd
CVE-2003-1066P4MEDIUMCVSS 5.0v5.7v5.82003-12-31
CVE-2003-1066 [MEDIUM] CVE-2003-1066: Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a de
Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.
nvd
CVE-2012-4287P4MEDIUMCVSS 5.0v5.112012-08-16
CVE-2012-4287 [MEDIUM] CWE-399 CVE-2012-4287: epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remot
epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length.
nvd
CVE-1999-0189P4HIGHCVSS 7.5v5.3v5.4+2 more1997-06-04
CVE-1999-0189 [HIGH] CVE-1999-0189: Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard po
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
nvd
CVE-2003-0914P4MEDIUMCVSS 4.3v5.7v5.82003-12-15
CVE-2003-0914 [MEDIUM] CVE-2003-0914: ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
nvd
CVE-2006-5201P4MEDIUMCVSS 4.0v5.82006-10-10
CVE-2006-5201 [MEDIUM] CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier,
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which all
nvd
CVE-2002-1296P4HIGHCVSS 7.2v5.5.1v5.7+1 more2002-12-23
CVE-2002-1296 [HIGH] CVE-2002-1296: Directory traversal vulnerability in priocntl system call in Solaris does allows local users to exec
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
nvd
CVE-2003-1057P4HIGHCVSS 7.2v5.7v5.82003-12-08
CVE-2003-1057 [HIGH] CVE-2003-1057: Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow loca
Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.
nvd
CVE-1999-1438P4HIGHCVSS 7.2≤ 4.1.1v4.0.3+1 more1991-02-22
CVE-1999-1438 [HIGH] CVE-1999-1438: Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via
Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.
nvd
CVE-1999-0840P4HIGHCVSS 7.2v5.71999-11-30
CVE-1999-0840 [HIGH] CVE-1999-0840: Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long
Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
nvd
CVE-2002-0088P4HIGHCVSS 7.2v5.72002-03-15
CVE-2002-0088 [HIGH] CVE-2002-0088: Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
nvd
CVE-1999-0056P4HIGHCVSS 7.2v5.3v5.4+2 more1998-09-09
CVE-1999-0056 [HIGH] CVE-1999-0056: Buffer overflow in Sun's ping program can give root access to local users.
Buffer overflow in Sun's ping program can give root access to local users.
nvd
CVE-2003-1024P4HIGHCVSS 7.2v5.82004-01-20
CVE-2003-1024 [HIGH] CVE-2003-1024: Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create
Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.
nvd
CVE-1999-1585P4HIGHCVSS 7.2v5.01999-12-31
CVE-1999-1585 [HIGH] CVE-1999-1585: The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged sh
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
nvd
CVE-1999-0134P4HIGHCVSS 7.2v5.4v5.5+1 more1996-08-06
CVE-1999-0134 [HIGH] CVE-1999-0134: vold in Solaris 2.x allows local users to gain root access.
vold in Solaris 2.x allows local users to gain root access.
nvd
CVE-2000-0055P4HIGHCVSS 7.2v5.3v5.4+3 more2000-01-06
CVE-2000-0055 [HIGH] CVE-2000-0055: Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n opti
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
nvd
CVE-2005-4795P4HIGHCVSS 7.2v5.7v5.82005-12-31
CVE-2005-4795 [HIGH] CVE-2005-4795: Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as
Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.
nvd