cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 23 of 27
CVE-2008-2708P4MEDIUMCVSS 4.9v5.102008-06-16
CVE-2008-2708 [MEDIUM] CVE-2008-2708: Unspecified vulnerability in the Sun (1) UltraSPARC T2 and (2) UltraSPARC T2+ kernel modules in Sun Unspecified vulnerability in the Sun (1) UltraSPARC T2 and (2) UltraSPARC T2+ kernel modules in Sun Solaris 10, and OpenSolaris before snv_93, allows local users to cause a denial of service (panic) via unspecified vectors, probably related to core files.
nvd
CVE-2011-0813P4MEDIUMCVSS 4.9v5.8v5.9+2 more2011-04-20
CVE-2011-0813 [MEDIUM] CVE-2011-0813: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect av Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2012-0098.
nvd
CVE-2012-3212P4MEDIUMCVSS 4.7v5.10v5.112012-10-17
CVE-2012-3212 [MEDIUM] CVE-2012-3212: Unspecified vulnerability in Oracle Sun Solaris 10 and 11, when running on SPARC T4 servers, allows Unspecified vulnerability in Oracle Sun Solaris 10 and 11, when running on SPARC T4 servers, allows local users to affect availability via unknown vectors related to Kernel.
nvd
CVE-1999-0167P4MEDIUMCVSS 4.6v4.1.11991-12-06
CVE-1999-0167 [MEDIUM] CVE-1999-0167: In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.
nvd
CVE-2004-2306P4MEDIUMCVSS 4.6v5.7v5.82004-12-31
CVE-2004-2306 [MEDIUM] CVE-2004-2306: Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has be Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection.
nvd
CVE-1999-0370P4MEDIUMCVSS 4.6v5.4v5.5+2 more1999-02-10
CVE-1999-0370 [MEDIUM] CVE-1999-0370: In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary fi In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
nvd
CVE-1999-0132P4LOWCVSS 2.1v4.1.1v4.1.2+8 more1996-08-15
CVE-1999-0132 [LOW] CVE-1999-0132: Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root acce Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
nvd
CVE-2010-4442P4MEDIUMCVSS 4.4v5.10v5.112011-01-19
CVE-2010-4442 [MEDIUM] CVE-2010-4442: Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availabil Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.
nvd
CVE-2010-4440P4MEDIUMCVSS 4.4v5.10v5.112011-01-19
CVE-2010-4440 [MEDIUM] CVE-2010-4440: Unspecified vulnerability in Oracle 10 and 11 Express allows local users to affect availability via Unspecified vulnerability in Oracle 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.
nvd
CVE-2011-2313P4MEDIUMCVSS 4.3v5.102011-10-18
CVE-2011-2313 [MEDIUM] CVE-2011-2313: Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to ZFS, a different vulnerability than CVE-2011-2311.
nvd
CVE-2010-4458P4MEDIUMCVSS 4.1v5.112011-01-19
CVE-2010-4458 [MEDIUM] CVE-2010-4458: Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, re Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, related to ZFS.
nvd
CVE-2012-0099P4LOWCVSS 2.6v5.9v5.10+1 more2012-01-18
CVE-2012-0099 [LOW] CVE-2012-0099: Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to sshd.
nvd
CVE-2012-1698P4LOWCVSS 2.1v5.112012-05-03
CVE-2012-1698 [LOW] CVE-2012-1698: Unspecified vulnerability in Oracle Sun Solaris 11 allows remote authenticated users to affect confi Unspecified vulnerability in Oracle Sun Solaris 11 allows remote authenticated users to affect confidentiality, related to Kernel/GLD.
nvd
CVE-2008-0269P4MEDIUMCVSS 4.9v5.102008-01-15
CVE-2008-0269 [MEDIUM] CVE-2008-0269: Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.
nvd
CVE-2007-5921P4MEDIUMCVSS 4.7v5.9v5.102007-11-10
CVE-2007-5921 [MEDIUM] CVE-2007-5921: Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris 9 and 10 allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2004-1346.
nvd
CVE-2007-2465P4MEDIUMCVSS 4.7v5.92007-05-02
CVE-2007-2465 [MEDIUM] CVE-2007-2465: Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, wr Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.
nvd
CVE-2001-1503P4LOWCVSS 2.1v5.5v5.5.1+3 more2001-12-31
CVE-2001-1503 [LOW] CVE-2001-1503: The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
nvd
CVE-2002-1323P4MEDIUMCVSS 4.6v5.82002-12-11
CVE-2002-1323 [MEDIUM] CVE-2002-1323: Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
nvd
CVE-2001-1555P4MEDIUMCVSS 4.6v5.82001-12-31
CVE-2001-1555 [MEDIUM] CVE-2001-1555: pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of termi pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.
nvd
CVE-1999-1025P4MEDIUMCVSS 4.6v5.61998-11-12
CVE-1999-1025 [MEDIUM] CVE-1999-1025: CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's co CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
nvd
Sun Sunos vulnerabilities | cvebase