Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 24 of 27
CVE-2002-1763P4MEDIUMCVSS 4.6v5.82002-12-31
CVE-2002-1763 [MEDIUM] CVE-2002-1763: The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed re
The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.
nvd
CVE-2012-4285P4LOWCVSS 3.3v5.112012-08-16
CVE-2012-4285 [LOW] CWE-189 CVE-2012-4285: The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.
nvd
CVE-2013-0404P4LOWCVSS 3.7v5.102013-04-17
CVE-2013-0404 [LOW] CVE-2013-0404: Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, int
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Boot.
nvd
CVE-2006-0227P4LOWCVSS 2.6v5.8v5.92006-01-17
CVE-2006-0227 [LOW] CVE-2006-0227: Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to del
Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.
nvd
CVE-2002-2203P4MEDIUMCVSS 4.9v5.5.1v5.72002-12-31
CVE-2002-2203 [MEDIUM] CVE-2002-2203: Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows loca
Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.
nvd
CVE-1999-0129P4MEDIUMCVSS 4.6v4.1.3u1v4.1.4+4 more1996-12-03
CVE-1999-0129 [MEDIUM] CVE-1999-0129: Sendmail allows local users to write to a file and gain group permissions via a .forward or :include
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
nvd
CVE-1999-1023P4MEDIUMCVSS 4.6v5.71999-06-10
CVE-1999-1023 [MEDIUM] CVE-1999-1023: useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (ex
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.
nvd
CVE-2010-3586P4LOWCVSS 3.6v5.92011-01-19
CVE-2010-3586 [LOW] CVE-2010-3586: Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integ
Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.
nvd
CVE-2010-4460P4LOWCVSS 3.6v5.102011-01-19
CVE-2010-4460 [LOW] CVE-2010-4460: Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and inte
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Fault Manager Daemon.
nvd
CVE-2012-0109P4LOWCVSS 3.6v5.8v5.9+2 more2012-01-18
CVE-2012-0109 [LOW] CVE-2012-0109: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect co
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality and availability, related to TCP/IP.
nvd
CVE-2006-5215P4LOWCVSS 2.6v5.8v5.92006-10-10
CVE-2006-5215 [LOW] CVE-2006-5215: The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 2006
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
nvd
CVE-2002-2327P4MEDIUMCVSS 4.9v5.82002-12-31
CVE-2002-2327 [MEDIUM] CWE-264 CVE-2002-2327: Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire
Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties.
nvd
CVE-2006-0161P4MEDIUMCVSS 4.6v5.82006-01-10
CVE-2006-0161 [MEDIUM] CVE-2006-0161: Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOT
Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.
nvd
CVE-1999-0303P4MEDIUMCVSS 4.6v4.1.3v4.1.4+7 more1998-05-21
CVE-1999-0303 [MEDIUM] CVE-1999-0303: Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
nvd
CVE-2006-1782P4LOWCVSS 2.1v5.82006-04-13
CVE-2006-1782 [LOW] CVE-2006-1782: Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server
Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.
nvd
CVE-2005-2032P4LOWCVSS 2.1v5.7v5.82005-06-16
CVE-2005-2032 [LOW] CVE-2005-2032: Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrar
Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.
nvd
CVE-2004-0654P4LOWCVSS 2.1v5.7v5.82004-08-06
CVE-2004-0654 [LOW] CVE-2004-0654: Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Admini
Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).
nvd
CVE-1999-1297P4LOWCVSS 2.1v4.1v4.1.1+3 more1998-07-15
CVE-1999-1297 [LOW] CVE-1999-1297: cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical a
cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.
nvd
CVE-2003-1072P4LOWCVSS 2.1v5.82003-04-28
CVE-2003-1072 [LOW] CVE-2003-1072: Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory c
Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).
nvd
CVE-2004-0481P4LOWCVSS 2.1v5.82005-02-23
CVE-2004-0481 [LOW] CVE-2004-0481: The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other ver
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
nvd