Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 17 of 27
CVE-2003-0058P4MEDIUMCVSS 5.0v5.82003-02-19
CVE-2003-0058 [MEDIUM] CVE-2003-0058: MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
nvd
CVE-2014-6518P4MEDIUMCVSS 6.6v5.10v5.112015-01-21
CVE-2014-6518 [MEDIUM] CVE-2014-6518: Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and ava
Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS).
nvd
CVE-2013-0400P4MEDIUMCVSS 6.6v5.9v5.102013-01-17
CVE-2013-0400 [MEDIUM] CVE-2013-0400: Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentialit
Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Filesystem/cachefs.
nvd
CVE-2011-0800P4MEDIUMCVSS 6.5v5.8v5.9+2 more2011-04-20
CVE-2011-0800 [MEDIUM] CVE-2011-0800: Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows
Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Administration Utilities.
nvd
CVE-2013-0415P4MEDIUMCVSS 6.0v5.102013-01-17
CVE-2013-0415 [MEDIUM] CVE-2013-0415: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, int
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package.
nvd
CVE-2002-1345P4MEDIUMCVSS 5.0v5.72002-12-23
CVE-2002-1345 [MEDIUM] CVE-2002-1345: Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious F
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
nvd
CVE-2013-0411P4MEDIUMCVSS 5.9v5.8v5.9+1 more2013-04-17
CVE-2013-0411 [MEDIUM] CVE-2013-0411: Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidenti
Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via vectors related to RBAC Configuration.
nvd
CVE-2012-1683P4MEDIUMCVSS 5.9v5.8v5.9+2 more2012-05-03
CVE-2012-1683 [MEDIUM] CVE-2012-1683: Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confid
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to gssd.
nvd
CVE-2005-0447P4MEDIUMCVSS 5.0v5.7v5.82005-02-15
CVE-2005-0447 [MEDIUM] CVE-2005-0447: Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certa
Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.
nvd
CVE-1999-1258P4MEDIUMCVSS 5.0≤ 4.1.1v4.11991-01-15
CVE-1999-1258 [MEDIUM] CVE-1999-1258: rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.
nvd
CVE-2011-2249P4MEDIUMCVSS 5.2v5.8v5.9+1 more2011-07-20
CVE-2011-2249 [MEDIUM] CVE-2011-2249: Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote authenticated users to affect
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote authenticated users to affect availability, related to TCP/IP.
nvd
CVE-1999-0334P4HIGHCVSS 7.2v5.01993-12-16
CVE-1999-0334 [HIGH] CVE-1999-0334: In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to o
In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.
nvd
CVE-1999-1396P4HIGHCVSS 7.2v4.1v4.1.1+1 more1992-07-21
CVE-1999-1396 [HIGH] CVE-1999-1396: Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through
Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).
nvd
CVE-2004-0800P4MEDIUMCVSS 4.6v5.82004-08-24
CVE-2004-0800 [MEDIUM] CVE-2004-0800: Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain pri
Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.
nvd
CVE-2005-3099P4MEDIUMCVSS 4.6v5.7v5.82005-09-28
CVE-2005-3099 [MEDIUM] CVE-2005-3099: Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows lo
Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.
nvd
CVE-2007-4310P4MEDIUMCVSS 4.3v5.7v5.8+1 more2007-08-13
CVE-2007-4310 [MEDIUM] CVE-2007-4310: The finger daemon (in.fingerd) in Sun Solaris 7 through 9 allows remote attackers to list all accoun
The finger daemon (in.fingerd) in Sun Solaris 7 through 9 allows remote attackers to list all accounts that have certain nonstandard GECOS fields via a request composed of a single digit, as demonstrated by a "finger 9@host" command, a different vulnerability than CVE-2001-1503.
nvd
CVE-2006-3664P4MEDIUMCVSS 5.0v5.8v5.92006-07-18
CVE-2006-3664 [MEDIUM] CVE-2006-3664: Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attacker
Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.
nvd
CVE-2012-1687P4MEDIUMCVSS 5.6v5.10v5.112012-07-17
CVE-2012-1687 [MEDIUM] CVE-2012-1687: Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and ava
Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability, related to Logical Domains (LDOM).
nvd
CVE-2004-1348P4MEDIUMCVSS 5.0v5.82004-09-06
CVE-2004-1348 [MEDIUM] CVE-2004-1348: Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service
Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).
nvd
CVE-2008-5550P4MEDIUMCVSS 4.3v5.102008-12-12
CVE-2008-5550 [MEDIUM] CVE-2008-5550: Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.
nvd