cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 3 of 27
CVE-1999-0517P4MEDIUMCVSS 5.9PoCv5.01997-01-01
CVE-1999-0517 [MEDIUM] CWE-200 CVE-1999-0517: An SNMP community name is the default (e.g. public), null, or missing. An SNMP community name is the default (e.g. public), null, or missing.
nvd
CVE-2000-0032P4CRITICALCVSS 10.0PoCv5.71999-12-22
CVE-2000-0032 [CRITICAL] CVE-2000-0032: Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.
nvd
CVE-2001-1244P4MEDIUMCVSS 5.0PoCv5.5.1v5.7+1 more2001-07-07
CVE-2001-1244 [MEDIUM] CVE-2001-1244: Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth an Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
nvd
CVE-1999-1191P4HIGHCVSS 7.2PoC≤ 5.5.1v5.4+1 more1997-05-19
CVE-1999-1191 [HIGH] CVE-1999-1191: Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
nvd
CVE-2004-0523P3CRITICALCVSS 10.0v5.82004-08-18
CVE-2004-0523 [CRITICAL] CVE-2004-0523: Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier all Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.
nvd
CVE-2005-3398P4MEDIUMCVSS 4.3PoCv5.82005-11-01
CVE-2005-3398 [MEDIUM] CWE-200 CVE-2005-3398: The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9 The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.
nvd
CVE-1999-1432P4HIGHCVSS 7.5PoCv5.4v5.5+1 more1998-07-16
CVE-1999-1432 [HIGH] CVE-1999-1432: Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
nvd
CVE-2000-0471P4HIGHCVSS 7.2PoCv4.1.3v4.1.4+10 more2000-06-14
CVE-2000-0471 [HIGH] CVE-2000-0471: Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges vi Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
nvd
CVE-2001-0115P4HIGHCVSS 7.2PoCv5.4v5.5+2 more2001-03-12
CVE-2001-0115 [HIGH] CVE-2001-0115: Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary comm Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
nvd
CVE-1999-1123P4HIGHCVSS 7.2PoCv4.0.3v4.1+1 more1991-05-20
CVE-1999-1123 [HIGH] CVE-1999-1123: The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.
nvd
CVE-2005-2072P4HIGHCVSS 7.2PoCv5.82005-06-29
CVE-2005-2072 [HIGH] CWE-264 CVE-2005-2072: The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setui The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
nvd
CVE-2001-0652P4HIGHCVSS 7.2PoC≤ 5.92001-10-30
CVE-2001-0652 [HIGH] CVE-2001-0652: Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a lon Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
nvd
CVE-2007-3093P3CRITICALCVSS 10.0v5.8v5.9+1 more2007-06-06
CVE-2007-3093 [CRITICAL] CVE-2007-3093: Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solari Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.
nvd
CVE-2001-0421P4MEDIUMCVSS 6.4PoC≤ 5.92001-07-02
CVE-2001-0421 [MEDIUM] CVE-2001-0421: FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the ro FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
nvd
CVE-2011-3508P3CRITICALCVSS 9.3v5.8v5.9+2 more2011-10-18
CVE-2011-3508 [CRITICAL] CVE-2011-3508: Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affe Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect confidentiality, integrity, and availability, related to LDAP library.
nvd
CVE-2001-0422P4HIGHCVSS 7.2PoCv5.3v5.4+4 more2001-07-02
CVE-2001-0422 [HIGH] CVE-2001-0422: Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands vi Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
nvd
CVE-2000-0317P4HIGHCVSS 7.2PoCv5.72000-04-24
CVE-2000-0317 [HIGH] CVE-2000-0317: Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option. Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
nvd
CVE-2004-2686P4HIGHCVSS 7.2PoCv5.7v5.8+1 more2004-12-31
CVE-2004-2686 [HIGH] CVE-2004-2686: Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows lo Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.
nvd
CVE-2001-0426P4HIGHCVSS 7.2PoCv5.7v5.82001-07-02
CVE-2001-0426 [HIGH] CVE-2001-0426: Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
nvd
CVE-2000-0337P4HIGHCVSS 7.2PoCv5.7v5.82000-04-24
CVE-2000-0337 [HIGH] CVE-2000-0337: Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
nvd
Sun Sunos vulnerabilities | cvebase