Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 15 of 27
CVE-2013-0406P4MEDIUMCVSS 4.3v5.102013-04-17
CVE-2013-0406 [MEDIUM] CVE-2013-0406: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via u
Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors via vectors related to Kernel/IPsec.
nvd
CVE-2007-2882P4MEDIUMCVSS 5.0v5.8v5.9+1 more2007-05-30
CVE-2007-2882 [MEDIUM] CVE-2007-2882: Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when
Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.
nvd
CVE-2006-3920P4MEDIUMCVSS 5.0v5.82006-07-28
CVE-2006-3920 [MEDIUM] CVE-2006-3920: The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause
The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause a denial of service (resource exhaustion) via a TCP packet with an incorrect sequence number, which triggers an ACK storm.
nvd
CVE-2007-2045P4MEDIUMCVSS 5.0v5.8v5.92007-04-16
CVE-2007-2045 [MEDIUM] CVE-2007-2045: Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to
Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments.
nvd
CVE-2006-3728P4MEDIUMCVSS 6.8v5.102006-07-21
CVE-2006-3728 [MEDIUM] CVE-2006-3728: Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and wi
Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption."
nvd
CVE-1999-0277P4HIGHCVSS 7.2v5.01996-10-28
CVE-1999-0277 [HIGH] CVE-1999-0277: The WorkMan program can be used to overwrite any file to get root access.
The WorkMan program can be used to overwrite any file to get root access.
nvd
CVE-1999-1021P4HIGHCVSS 7.2v4.1v4.1.1+1 more1992-12-30
CVE-1999-1021 [HIGH] CVE-1999-1021: NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
nvd
CVE-1999-0120P4HIGHCVSS 7.2v4.11994-03-21
CVE-1999-0120 [HIGH] CVE-1999-0120: Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than r
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.
nvd
CVE-1999-1142P4HIGHCVSS 7.2≤ 4.1.21992-05-27
CVE-1999-1142 [HIGH] CVE-1999-1142: SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to
SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.
nvd
CVE-2001-0470P4HIGHCVSS 7.2v5.82001-06-27
CVE-2001-0470 [HIGH] CVE-2001-0470: Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
nvd
CVE-2001-0190P4HIGHCVSS 7.2≤ 5.8v5.4+3 more2001-03-26
CVE-2001-0190 [HIGH] CVE-2001-0190: Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, all
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
nvd
CVE-2001-0124P4HIGHCVSS 7.2v5.4v5.5+1 more2001-03-12
CVE-2001-0124 [HIGH] CVE-2001-0124: Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileg
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
nvd
CVE-2014-6481P4MEDIUMCVSS 4.3v5.10v5.112015-01-21
CVE-2014-6481 [MEDIUM] CVE-2014-6481: Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidential
Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidentiality via vectors related to KSSL.
nvd
CVE-2014-4225P4MEDIUMCVSS 6.9v5.102014-07-17
CVE-2014-4225 [MEDIUM] CVE-2014-4225: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, int
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Patch installation scripts.
nvd
CVE-2012-0100P4MEDIUMCVSS 6.8v5.9v5.10+1 more2012-01-18
CVE-2012-0100 [MEDIUM] CVE-2012-0100: Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confi
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kerberos.
nvd
CVE-2012-1691P4MEDIUMCVSS 6.6v5.112012-05-03
CVE-2012-1691 [MEDIUM] CVE-2012-1691: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, int
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Privileges.
nvd
CVE-2002-1199P4MEDIUMCVSS 5.0v5.7v5.82002-10-28
CVE-2002-1199 [MEDIUM] CVE-2002-1199: The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to r
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
nvd
CVE-1999-0300P4HIGHCVSS 7.5v5.3v5.4+2 more1997-10-01
CVE-1999-0300 [HIGH] CVE-1999-0300: nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
nvd
CVE-2013-0408P4MEDIUMCVSS 5.0v5.102013-04-17
CVE-2013-0408 [MEDIUM] CVE-2013-0408: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vec
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to CPU performance counters drivers.
nvd
CVE-1999-1507P4HIGHCVSS 7.2v4.1v4.1.1+5 more1993-02-03
CVE-1999-1507 [HIGH] CVE-1999-1507: Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on f
Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.
nvd