Sun Sunos vulnerabilities
537 known vulnerabilities affecting sun/sunos.
Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91
Vulnerabilities
Page 5 of 27
CVE-1999-0032P4HIGHCVSS 7.2PoCv4.1.3u1v4.1.41996-10-25
CVE-1999-0032 [HIGH] CVE-1999-0032: Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
nvd
CVE-1999-1371P4HIGHCVSS 7.2PoCv5.5.1v5.71999-03-08
CVE-1999-1371 [HIGH] CVE-1999-1371: Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a l
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.
nvd
CVE-1999-1467P3CRITICALCVSS 10.0v4.0v4.0.1+3 more1989-10-26
CVE-1999-1467 [CRITICAL] CVE-1999-1467: Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary
Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.
nvd
CVE-2004-1351P3CRITICALCVSS 10.0v5.7v5.82004-12-07
CVE-2004-1351 [CRITICAL] CVE-2004-1351: Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers
Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.
nvd
CVE-2001-1582P4HIGHCVSS 7.2PoCv5.82001-12-31
CVE-2001-1582 [HIGH] CWE-119 CVE-2001-1582: Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users t
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
nvd
CVE-2001-0165P4HIGHCVSS 7.2PoCv5.7v5.82001-05-03
CVE-2001-0165 [HIGH] CVE-2001-0165: Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privi
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
nvd
CVE-2000-0118P4HIGHCVSS 7.2PoCv4.1.3v4.1.4+6 more1999-06-09
CVE-2000-0118 [HIGH] CVE-2000-0118: The Red Hat Linux su program does not log failed password guesses if the su process is killed before
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
nvd
CVE-2003-0196P3CRITICALCVSS 10.0v5.5.1v5.7+1 more2003-05-05
CVE-2003-0196 [CRITICAL] CVE-2003-0196: Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary cod
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
nvd
CVE-2012-4297P3HIGHCVSS 8.3v5.112012-08-16
CVE-2012-4297 [HIGH] CWE-119 CVE-2012-4297: Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c i
Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in Wireshark 1.6.x before 1.6.10 and 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a malformed packet.
nvd
CVE-2008-1480P4MEDIUMCVSS 4.3PoCv5.102008-03-24
CVE-2008-1480 [MEDIUM] CVE-2008-1480: rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.
nvd
CVE-2002-0572P4HIGHCVSS 7.2PoCv5.5.1v5.7+1 more2002-07-03
CVE-2002-0572 [HIGH] CVE-2002-0572: FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
nvd
CVE-2001-1076P4HIGHCVSS 7.2PoCv5.5v5.5.1+2 more2001-07-05
CVE-2001-1076 [HIGH] CVE-2001-1076: Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
nvd
CVE-1999-0051P4HIGHCVSS 7.2PoCv4.1.1v4.1.2+7 more1997-01-06
CVE-1999-0051 [HIGH] CVE-1999-0051: Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0,
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
nvd
CVE-2002-0797P3CRITICALCVSS 10.0v5.6v5.7+1 more2002-08-12
CVE-2002-0797 [CRITICAL] CVE-2002-0797: Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote atta
Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
nvd
CVE-2002-1584P3CRITICALCVSS 10.0v5.5.1v5.72002-12-27
CVE-2002-1584 [CRITICAL] CVE-2002-1584: Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX
Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.
nvd
CVE-1999-0767P4HIGHCVSS 7.2PoCv5.71999-09-08
CVE-1999-0767 [HIGH] CVE-1999-0767: Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
nvd
CVE-2001-0595P4MEDIUMCVSS 4.6PoCv5.7v5.82001-08-02
CVE-2001-0595 [MEDIUM] CVE-2001-0595: Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute
Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.
nvd
CVE-2001-0403P4HIGHCVSS 7.2PoCv5.02001-06-18
CVE-2001-0403 [HIGH] CVE-2001-0403: /opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
nvd
CVE-2002-0796P3CRITICALCVSS 10.0v5.6v5.7+1 more2002-08-12
CVE-2002-0796 [CRITICAL] CVE-2002-0796: Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remo
Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
nvd
CVE-1999-0974P3CRITICALCVSS 10.0v5.4v5.5+2 more1999-12-09
CVE-1999-0974 [CRITICAL] CVE-1999-0974: Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA reques
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
nvd