cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 14 of 27
CVE-1999-1211P4HIGHCVSS 7.2≤ 4.1.11991-03-27
CVE-1999-1211 [HIGH] CVE-1999-1211: Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges. Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.
nvd
CVE-1999-0952P4HIGHCVSS 7.2v5.71999-01-28
CVE-1999-0952 [HIGH] CVE-1999-0952: Buffer overflow in Solaris lpstat via class argument allows local users to gain root access. Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
nvd
CVE-2013-3837P4MEDIUMCVSS 4.3v5.102013-10-16
CVE-2013-3837 [MEDIUM] CVE-2013-3837: Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows remote attackers to affect availabili Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows remote attackers to affect availability via unknown vectors related to Cacao.
nvd
CVE-2006-6494P4MEDIUMCVSS 6.6v5.82006-12-13
CVE-2006-6494 [MEDIUM] CVE-2006-6494: Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execu Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.
nvd
CVE-2003-1066P4MEDIUMCVSS 5.0v5.7v5.82003-12-31
CVE-2003-1066 [MEDIUM] CVE-2003-1066: Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a de Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.
nvd
CVE-2012-4287P4MEDIUMCVSS 5.0v5.112012-08-16
CVE-2012-4287 [MEDIUM] CWE-399 CVE-2012-4287: epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remot epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length.
nvd
CVE-1999-0189P4HIGHCVSS 7.5v5.3v5.4+2 more1997-06-04
CVE-1999-0189 [HIGH] CVE-1999-0189: Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard po Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
nvd
CVE-2003-0914P4MEDIUMCVSS 4.3v5.7v5.82003-12-15
CVE-2003-0914 [MEDIUM] CVE-2003-0914: ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
nvd
CVE-2006-5201P4MEDIUMCVSS 4.0v5.82006-10-10
CVE-2006-5201 [MEDIUM] CVE-2006-5201: Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which all
nvd
CVE-2002-1296P4HIGHCVSS 7.2v5.5.1v5.7+1 more2002-12-23
CVE-2002-1296 [HIGH] CVE-2002-1296: Directory traversal vulnerability in priocntl system call in Solaris does allows local users to exec Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
nvd
CVE-2003-1057P4HIGHCVSS 7.2v5.7v5.82003-12-08
CVE-2003-1057 [HIGH] CVE-2003-1057: Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow loca Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.
nvd
CVE-1999-1438P4HIGHCVSS 7.2≤ 4.1.1v4.0.3+1 more1991-02-22
CVE-1999-1438 [HIGH] CVE-1999-1438: Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.
nvd
CVE-1999-0840P4HIGHCVSS 7.2v5.71999-11-30
CVE-1999-0840 [HIGH] CVE-1999-0840: Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
nvd
CVE-2002-0088P4HIGHCVSS 7.2v5.72002-03-15
CVE-2002-0088 [HIGH] CVE-2002-0088: Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
nvd
CVE-1999-0056P4HIGHCVSS 7.2v5.3v5.4+2 more1998-09-09
CVE-1999-0056 [HIGH] CVE-1999-0056: Buffer overflow in Sun's ping program can give root access to local users. Buffer overflow in Sun's ping program can give root access to local users.
nvd
CVE-2003-1024P4HIGHCVSS 7.2v5.82004-01-20
CVE-2003-1024 [HIGH] CVE-2003-1024: Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.
nvd
CVE-1999-1585P4HIGHCVSS 7.2v5.01999-12-31
CVE-1999-1585 [HIGH] CVE-1999-1585: The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged sh The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
nvd
CVE-1999-0134P4HIGHCVSS 7.2v5.4v5.5+1 more1996-08-06
CVE-1999-0134 [HIGH] CVE-1999-0134: vold in Solaris 2.x allows local users to gain root access. vold in Solaris 2.x allows local users to gain root access.
nvd
CVE-2000-0055P4HIGHCVSS 7.2v5.3v5.4+3 more2000-01-06
CVE-2000-0055 [HIGH] CVE-2000-0055: Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n opti Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
nvd
CVE-2005-4795P4HIGHCVSS 7.2v5.7v5.82005-12-31
CVE-2005-4795 [HIGH] CVE-2005-4795: Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.
nvd
Sun Sunos vulnerabilities | cvebase