Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 2 of 27
CVE-2002-1317P3HIGHCVSS 7.5PoCv5.5.1v5.7+1 more2002-12-11
CVE-2002-1317 [HIGH] CVE-2002-1317: Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allow
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
nvd
CVE-1999-0009P3CRITICALCVSS 10.0PoCv5.3v5.4+2 more1998-04-08
CVE-1999-0009 [CRITICAL] CVE-1999-0009: Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
nvd
CVE-2002-0436P3CRITICALCVSS 10.0PoCv5.7v5.82002-07-26
CVE-2002-0436 [CRITICAL] CVE-2002-0436: sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitra
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.
nvd
CVE-2000-0844P3CRITICALCVSS 10.0PoCv5.0v5.1+7 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-1999-0210P3CRITICALCVSS 10.0PoCv5.4v5.5+1 more1997-11-26
CVE-1999-0210 [CRITICAL] CVE-1999-0210: Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
nvd
CVE-2005-4797P3MEDIUMCVSS 5.0PoCv5.7v5.82005-12-31
CVE-2005-4797 [MEDIUM] CVE-2005-4797: Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows
Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via ".." sequences in an "Unlink data file" command.
nvd
CVE-1999-0128P4MEDIUMCVSS 5.0PoCv5.4v5.5+1 more1996-12-18
CVE-1999-0128 [MEDIUM] CVE-1999-0128: Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
nvd
CVE-1999-0973P3CRITICALCVSS 10.0PoCv5.3v5.4+3 more1999-12-07
CVE-1999-0973 [CRITICAL] CVE-1999-0973: Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
nvd
CVE-1999-0696P3CRITICALCVSS 10.0PoCv4.1.3v5.3+3 more1999-07-01
CVE-1999-0696 [CRITICAL] CVE-1999-0696: Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
nvd
CVE-1999-0513P4MEDIUMCVSS 5.0PoCv5.4v5.5+1 more1998-01-05
CVE-1999-0513 [MEDIUM] CVE-1999-0513: ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denia
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
nvd
CVE-2002-0391P3CRITICALCVSS 9.8v5.5.1v5.7+1 more2002-08-12
CVE-2002-0391 [CRITICAL] CWE-190 CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
nvd
CVE-2003-0027P3MEDIUMCVSS 5.0PoCv5.5.1v5.7+1 more2003-02-07
CVE-2003-0027 [MEDIUM] CVE-2003-0027: Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.
nvd
CVE-2007-0165P3HIGHCVSS 7.8PoCv5.82007-01-10
CVE-2007-0165 [HIGH] CVE-2007-0165: Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial
Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.
nvd
CVE-1999-0209P4MEDIUMCVSS 5.0PoCv3.5v4.0+5 more1990-08-14
CVE-1999-0209 [MEDIUM] CVE-1999-0209: The SunView (SunTools) selection_svc facility allows remote users to read files.
The SunView (SunTools) selection_svc facility allows remote users to read files.
nvd
CVE-2003-0609P4HIGHCVSS 7.2PoCv5.7v5.82003-08-27
CVE-2003-0609 [HIGH] CVE-2003-0609: Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local us
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.
nvd
CVE-1999-0493P4HIGHCVSS 7.5PoCv5.3v5.4+1 more1999-06-07
CVE-1999-0493 [HIGH] CVE-1999-0493: rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
nvd
CVE-2004-0791P4MEDIUMCVSS 5.0PoCv5.7v5.82005-04-12
CVE-2004-0791 [MEDIUM] CVE-2004-0791: Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (networ
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2
nvd
CVE-2002-0679P3CRITICALCVSS 10.0v5.5.1v5.7+1 more2002-09-05
CVE-2002-0679 [CRITICAL] CVE-2002-0679: Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) a
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
nvd
CVE-2008-0965P3CRITICALCVSS 9.3v5.8v5.9+1 more2008-08-08
CVE-2008-0965 [CRITICAL] CWE-134 CVE-2008-0965: Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before s
Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.
nvd
CVE-2008-2144P3CRITICALCVSS 10.0v5.8v5.9+1 more2008-05-12
CVE-2008-2144 [CRITICAL] CVE-2008-2144: Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow rem
Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.
nvd