cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 16 of 27
CVE-1999-1197P4HIGHCVSS 7.2v4.1.11990-12-20
CVE-1999-1197 [HIGH] CVE-1999-1197: TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect cons TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.
nvd
CVE-1999-0295P4HIGHCVSS 7.2v5.3v5.4+2 more1997-10-01
CVE-1999-0295 [HIGH] CVE-1999-0295: Solaris sysdef command allows local users to read kernel memory, potentially leading to root privile Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
nvd
CVE-2014-4239P4MEDIUMCVSS 4.0v5.8v5.9+1 more2014-07-17
CVE-2014-4239 [MEDIUM] CVE-2014-4239: Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Common Agent Container (Cacao).
nvd
CVE-2012-3187P4MEDIUMCVSS 6.9v5.102012-10-17
CVE-2012-3187 [MEDIUM] CVE-2012-3187: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, int Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.
nvd
CVE-2014-6470P4MEDIUMCVSS 6.8v5.112014-10-15
CVE-2014-6470 [MEDIUM] CVE-2014-6470: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, int Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Archive Utility.
nvd
CVE-2013-0399P4MEDIUMCVSS 6.6v5.9v5.102013-01-17
CVE-2013-0399 [MEDIUM] CVE-2013-0399: Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentialit Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Umount.
nvd
CVE-2004-1354P4MEDIUMCVSS 5.0v5.82004-05-14
CVE-2004-1354 [MEDIUM] CWE-22 CVE-2004-1354: The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages w The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.
nvd
CVE-2012-0539P4MEDIUMCVSS 6.2v5.8v5.9+1 more2012-05-03
CVE-2012-0539 [MEDIUM] CVE-2012-0539: Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidenti Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to (1) bsmconv and (2) bsmunconv.
nvd
CVE-2013-5834P4MEDIUMCVSS 6.2v5.82014-01-15
CVE-2013-5834 [MEDIUM] CVE-2013-5834: Unspecified vulnerability in Oracle Solaris 8 allows local users to affect confidentiality, integrit Unspecified vulnerability in Oracle Solaris 8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ps.
nvd
CVE-1999-0104P4MEDIUMCVSS 5.0v4.1.3u1v4.1.41997-12-16
CVE-1999-0104 [MEDIUM] CVE-1999-0104: A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
nvd
CVE-2013-3786P4MEDIUMCVSS 6.0v5.9v5.10+1 more2013-07-17
CVE-2013-3786 [MEDIUM] CVE-2013-3786: Unspecified vulnerability in Oracle Solaris 9, 10, and 11 allows local users to affect confidentiali Unspecified vulnerability in Oracle Solaris 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.
nvd
CVE-1999-0033P4HIGHCVSS 7.2v5.3v5.4+2 more1997-06-12
CVE-1999-0033 [HIGH] CVE-1999-0033: Command execution in Sun systems via buffer overflow in the at program. Command execution in Sun systems via buffer overflow in the at program.
nvd
CVE-1999-1586P4HIGHCVSS 7.2v4.1.1v4.1.2+2 more1999-12-31
CVE-1999-1586 [HIGH] CVE-1999-1586: loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allow loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.
nvd
CVE-2002-1871P4HIGHCVSS 7.2v5.5.1v5.7+1 more2002-12-31
CVE-2002-1871 [HIGH] CVE-2002-1871: pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
nvd
CVE-1999-1080P4HIGHCVSS 7.2v5.71995-05-10
CVE-1999-1080 [HIGH] CVE-1999-1080: rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentati rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specif
nvd
CVE-2003-1076P4HIGHCVSS 7.2v5.7v5.82003-12-31
CVE-2003-1076 [HIGH] CVE-2003-1076: Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of se Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.
nvd
CVE-2003-1056P4HIGHCVSS 7.2v5.7v5.82003-12-11
CVE-2003-1056 [HIGH] CVE-2003-1056: The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary file The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-1999-1318P4HIGHCVSS 7.2≤ 4.1.3v4.1.1+3 more1993-09-17
CVE-1999-1318 [HIGH] CVE-1999-1318: /usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directo /usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.
nvd
CVE-2007-3717P4MEDIUMCVSS 6.9v5.8v5.9+1 more2007-07-12
CVE-2007-3717 [MEDIUM] CVE-2007-3717: rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.
nvd
CVE-1999-0024P4MEDIUMCVSS 5.0v5.3v5.4+2 more1997-08-13
CVE-1999-0024 [MEDIUM] CVE-1999-0024: DNS cache poisoning via BIND, by predictable query IDs. DNS cache poisoning via BIND, by predictable query IDs.
nvd
Sun Sunos vulnerabilities | cvebase