Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
0
Severity breakdown
CRITICAL51HIGH178MEDIUM217LOW91

Vulnerabilities

Page 20 of 27
CVE-2001-1244MEDIUMCVSS 5.0PoCv5.5.1v5.7+1 more2001-07-07
CVE-2001-1244 [MEDIUM] CVE-2001-1244: Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth an Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
nvd
CVE-2001-1076HIGHCVSS 7.2PoCv5.5v5.5.1+2 more2001-07-05
CVE-2001-1076 [HIGH] CVE-2001-1076: Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
nvd
CVE-2001-0426HIGHCVSS 7.2PoCv5.7v5.82001-07-02
CVE-2001-0426 [HIGH] CVE-2001-0426: Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
nvd
CVE-2001-0422HIGHCVSS 7.2PoCv5.3v5.4+4 more2001-07-02
CVE-2001-0422 [HIGH] CVE-2001-0422: Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands vi Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2001-0421MEDIUMCVSS 6.4PoC≤ 5.92001-07-02
CVE-2001-0421 [MEDIUM] CVE-2001-0421: FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the ro FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
nvd
CVE-2001-0470HIGHCVSS 7.2v5.82001-06-27
CVE-2001-0470 [HIGH] CVE-2001-0470: Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
nvd
CVE-2001-1328HIGHCVSS 7.5v5.4v5.5+4 more2001-06-22
CVE-2001-1328 [HIGH] CVE-2001-1328: Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitra Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.
nvd
CVE-2001-0401HIGHCVSS 7.2PoC≤ 5.9v5.5+2 more2001-06-18
CVE-2001-0401 [HIGH] CVE-2001-0401: Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2001-0403HIGHCVSS 7.2PoCv5.02001-06-18
CVE-2001-0403 [HIGH] CVE-2001-0403: /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
nvd
CVE-2001-0269CRITICALCVSS 10.0v5.82001-05-03
CVE-2001-0269 [CRITICAL] CVE-2001-0269: pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a N pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
nvd
CVE-2001-0236CRITICALCVSS 10.0PoCv5.7v5.82001-05-03
CVE-2001-0236 [CRITICAL] CVE-2001-0236: Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute ar Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
nvd
CVE-2001-0165HIGHCVSS 7.2PoCv5.7v5.82001-05-03
CVE-2001-0165 [HIGH] CVE-2001-0165: Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privi Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
nvd
CVE-2001-0190HIGHCVSS 7.2≤ 5.8v5.4+3 more2001-03-26
CVE-2001-0190 [HIGH] CVE-2001-0190: Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, all Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
nvd
CVE-2001-0124HIGHCVSS 7.2v5.4v5.5+1 more2001-03-12
CVE-2001-0124 [HIGH] CVE-2001-0124: Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileg Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
nvd
CVE-2001-0115HIGHCVSS 7.2PoCv5.4v5.5+2 more2001-03-12
CVE-2001-0115 [HIGH] CVE-2001-0115: Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary comm Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
nvd
CVE-2001-0059MEDIUMCVSS 6.2PoCv5.72001-02-12
CVE-2001-0059 [MEDIUM] CVE-2001-0059: patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack. patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2001-0095LOWCVSS 1.2PoCv5.7v5.82001-02-12
CVE-2001-0095 [LOW] CVE-2001-0095: catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack o catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
nvd
CVE-2000-0949HIGHCVSS 7.2PoCv5.5.12000-12-19
CVE-2000-0949 [HIGH] CVE-2000-0949: Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execut Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
nvd
CVE-2000-0844CRITICALCVSS 10.0PoCv5.0v5.1+7 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-2000-0471HIGHCVSS 7.2PoCv4.1.3v4.1.4+10 more2000-06-14
CVE-2000-0471 [HIGH] CVE-2000-0471: Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges vi Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
nvd