Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 26 of 27
CVE-2006-1780P4LOWCVSS 2.1v5.82006-04-13
CVE-2006-1780 [LOW] CVE-2006-1780: The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh cr
The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.
nvd
CVE-2006-1092P4LOWCVSS 2.1v5.82006-03-09
CVE-2006-1092 [LOW] CVE-2006-1092: Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8
Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to allocate a large amount of system memory that does not get freed.
nvd
CVE-2003-1065P4LOWCVSS 2.1v5.82003-07-23
CVE-2003-1065 [LOW] CVE-2003-1065: Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Sol
Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow local users to cause a denial of service (automountd crash).
nvd
CVE-2002-1586P4LOWCVSS 2.1v5.5.1v5.7+1 more2002-12-03
CVE-2002-1586 [LOW] CVE-2002-1586: Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting th
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.
nvd
CVE-2002-1587P4LOWCVSS 2.1v5.5.1v5.7+1 more2002-12-04
CVE-2002-1587 [LOW] CVE-2002-1587: The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a den
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.
nvd
CVE-2002-1589P4LOWCVSS 2.1v5.82002-10-24
CVE-2002-1589 [LOW] CVE-2002-1589: Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set i
Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).
nvd
CVE-2013-3842P4LOWCVSS 2.1v5.102013-10-16
CVE-2013-3842 [LOW] CVE-2013-3842: Unspecified vulnerability Oracle Solaris 10 allows local users to affect confidentiality via vectors
Unspecified vulnerability Oracle Solaris 10 allows local users to affect confidentiality via vectors related to Oracle Configuration Manager (OCM).
nvd
CVE-2011-0839P4LOWCVSS 3.7v5.9v5.10+1 more2011-04-20
CVE-2011-0839 [LOW] CVE-2011-0839: Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect avail
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect availability, related to LOFS.
nvd
CVE-2011-0812P4LOWCVSS 3.7v5.8v5.9+2 more2011-04-20
CVE-2011-0812 [LOW] CVE-2011-0812: Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows
Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel.
nvd
CVE-2003-0669P4LOWCVSS 1.2v5.7v5.82003-08-27
CVE-2003-0669 [LOW] CVE-2003-0669: Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare
Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.
nvd
CVE-2013-0414P4LOWCVSS 3.3v5.112013-01-17
CVE-2013-0414 [LOW] CVE-2013-0414: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availa
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via unknown vectors related to Utility/ksh93.
nvd
CVE-2011-0821P4LOWCVSS 3.0v5.8v5.9+1 more2011-04-20
CVE-2011-0821 [LOW] CVE-2011-0821: Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentialit
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors related to uucp.
nvd
CVE-2012-3122P4LOWCVSS 2.6v5.8v5.92012-07-17
CVE-2012-3122 [LOW] CVE-2012-3122: Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality
Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.
nvd
CVE-2011-0412P4LOWCVSS 2.1v5.8v5.9+1 more2011-04-19
CVE-2011-0412 [LOW] CWE-255 CVE-2011-0412: Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable per
Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.
nvd
CVE-2004-1356P4LOWCVSS 2.1v5.82004-04-23
CVE-2004-1356 [LOW] CVE-2004-1356: Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a
Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.
nvd
CVE-2009-4080P4LOWCVSS 2.1v5.8v5.9+1 more2009-11-29
CVE-2009-4080 [LOW] CVE-2009-4080: Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemo
Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 and 10, and OpenSolaris before snv_78, allow local users to cause a denial of service (daemon crash) via vectors involving multiple serviceSearchDescriptor attributes and a call to the getldap_lookup function, and unspecified other vectors.
nvd
CVE-2006-5214P4LOWCVSS 1.2v5.82006-10-10
CVE-2006-5214 [LOW] CVE-2006-5214: Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212,
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.
nvd
CVE-2005-4796P4LOWCVSS 3.6v5.5v5.5.1+2 more2005-12-31
CVE-2005-4796 [LOW] CVE-2005-4796: Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.
nvd
CVE-2013-5872P4LOWCVSS 2.1v5.102014-01-15
CVE-2013-5872 [LOW] CVE-2013-5872: Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability vi
Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to Name Service Cache Daemon (NSCD).
nvd
CVE-2014-6501P4LOWCVSS 2.1v5.112014-10-15
CVE-2014-6501 [LOW] CVE-2014-6501: Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via vectors related to SSH.
nvd