cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 24 of 27
CVE-2002-1763P4MEDIUMCVSS 4.6v5.82002-12-31
CVE-2002-1763 [MEDIUM] CVE-2002-1763: The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed re The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.
nvd
CVE-2012-4285P4LOWCVSS 3.3v5.112012-08-16
CVE-2012-4285 [LOW] CWE-189 CVE-2012-4285: The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.
nvd
CVE-2013-0404P4LOWCVSS 3.7v5.102013-04-17
CVE-2013-0404 [LOW] CVE-2013-0404: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, int Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Boot.
nvd
CVE-2006-0227P4LOWCVSS 2.6v5.8v5.92006-01-17
CVE-2006-0227 [LOW] CVE-2006-0227: Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to del Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.
nvd
CVE-2002-2203P4MEDIUMCVSS 4.9v5.5.1v5.72002-12-31
CVE-2002-2203 [MEDIUM] CVE-2002-2203: Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows loca Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.
nvd
CVE-1999-0129P4MEDIUMCVSS 4.6v4.1.3u1v4.1.4+4 more1996-12-03
CVE-1999-0129 [MEDIUM] CVE-1999-0129: Sendmail allows local users to write to a file and gain group permissions via a .forward or :include Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
nvd
CVE-1999-1023P4MEDIUMCVSS 4.6v5.71999-06-10
CVE-1999-1023 [MEDIUM] CVE-1999-1023: useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (ex useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.
nvd
CVE-2010-3586P4LOWCVSS 3.6v5.92011-01-19
CVE-2010-3586 [LOW] CVE-2010-3586: Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integ Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.
nvd
CVE-2010-4460P4LOWCVSS 3.6v5.102011-01-19
CVE-2010-4460 [LOW] CVE-2010-4460: Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and inte Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Fault Manager Daemon.
nvd
CVE-2012-0109P4LOWCVSS 3.6v5.8v5.9+2 more2012-01-18
CVE-2012-0109 [LOW] CVE-2012-0109: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect co Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality and availability, related to TCP/IP.
nvd
CVE-2006-5215P4LOWCVSS 2.6v5.8v5.92006-10-10
CVE-2006-5215 [LOW] CVE-2006-5215: The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 2006 The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
nvd
CVE-2002-2327P4MEDIUMCVSS 4.9v5.82002-12-31
CVE-2002-2327 [MEDIUM] CWE-264 CVE-2002-2327: Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties.
nvd
CVE-2006-0161P4MEDIUMCVSS 4.6v5.82006-01-10
CVE-2006-0161 [MEDIUM] CVE-2006-0161: Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOT Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.
nvd
CVE-1999-0303P4MEDIUMCVSS 4.6v4.1.3v4.1.4+7 more1998-05-21
CVE-1999-0303 [MEDIUM] CVE-1999-0303: Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames. Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
nvd
CVE-2006-1782P4LOWCVSS 2.1v5.82006-04-13
CVE-2006-1782 [LOW] CVE-2006-1782: Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.
nvd
CVE-2005-2032P4LOWCVSS 2.1v5.7v5.82005-06-16
CVE-2005-2032 [LOW] CVE-2005-2032: Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrar Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.
nvd
CVE-2004-0654P4LOWCVSS 2.1v5.7v5.82004-08-06
CVE-2004-0654 [LOW] CVE-2004-0654: Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Admini Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).
nvd
CVE-1999-1297P4LOWCVSS 2.1v4.1v4.1.1+3 more1998-07-15
CVE-1999-1297 [LOW] CVE-1999-1297: cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical a cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.
nvd
CVE-2003-1072P4LOWCVSS 2.1v5.82003-04-28
CVE-2003-1072 [LOW] CVE-2003-1072: Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory c Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).
nvd
CVE-2004-0481P4LOWCVSS 2.1v5.82005-02-23
CVE-2004-0481 [LOW] CVE-2004-0481: The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other ver The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
nvd
Sun Sunos vulnerabilities | cvebase