cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 6 of 27
CVE-2002-0573P3HIGHCVSS 7.5v5.7v5.82002-07-03
CVE-2002-0573 [HIGH] CVE-2002-0573: Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remot Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
nvd
CVE-2003-0028P3HIGHCVSS 7.5v5.5.1v5.7+1 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-2014-4276P3HIGHCVSS 7.5v5.112014-10-15
CVE-2014-4276 [HIGH] CVE-2014-4276: Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Common Internet File System (CIFS).
nvd
CVE-1999-0674P4HIGHCVSS 7.2PoCv5.1v5.2+5 more1999-08-09
CVE-1999-0674 [HIGH] CVE-1999-0674: The BSD profil system call allows a local user to modify the internal data space of a program via pr The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
nvd
CVE-2001-0269P3CRITICALCVSS 10.0v5.82001-05-03
CVE-2001-0269 [CRITICAL] CVE-2001-0269: pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a N pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
nvd
CVE-2007-4395P3HIGHCVSS 7.6v5.82007-08-17
CVE-2007-4395 [HIGH] CVE-2007-4395: Multiple unspecified vulnerabilities in the Role Based Access Control (RBAC) functionality in Sun So Multiple unspecified vulnerabilities in the Role Based Access Control (RBAC) functionality in Sun Solaris 8 allow remote attackers who know the password for a role to gain privileges via that role.
nvd
CVE-1999-0818P4HIGHCVSS 7.2PoCv5.71999-11-20
CVE-1999-0818 [HIGH] CVE-1999-0818: Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
nvd
CVE-2001-1328P3HIGHCVSS 7.5v5.4v5.5+4 more2001-06-22
CVE-2001-1328 [HIGH] CVE-2001-1328: Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitra Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.
nvd
CVE-2008-7300P3HIGHCVSS 8.5v5.102011-10-05
CVE-2008-7300 [HIGH] CWE-264 CVE-2008-7300: The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolari The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to the global zone.
nvd
CVE-2001-0353P3CRITICALCVSS 10.0v5.7v5.82001-07-21
CVE-2001-0353 [CRITICAL] CVE-2001-0353: Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remot Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
nvd
CVE-2013-3753P3HIGHCVSS 7.8v5.112013-07-17
CVE-2013-3753 [HIGH] CVE-2013-3753: Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via ve Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via vectors related to Kernel/STREAMS framework.
nvd
CVE-1999-0848P4MEDIUMCVSS 5.0PoCv5.71999-11-10
CVE-1999-0848 [MEDIUM] CVE-1999-0848: Denial of service in BIND named via consuming more than "fdmax" file descriptors. Denial of service in BIND named via consuming more than "fdmax" file descriptors.
nvd
CVE-2012-4294P3MEDIUMCVSS 5.8v5.112012-08-16
CVE-2012-4294 [MEDIUM] CWE-119 CVE-2012-4294: Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.
nvd
CVE-2014-6508P3HIGHCVSS 7.8v5.10v5.112014-10-15
CVE-2014-6508 [HIGH] CVE-2014-6508: Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availabi Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to iSCSI Data Mover (IDM).
nvd
CVE-2013-3748P3HIGHCVSS 7.8v5.112013-07-17
CVE-2013-3748 [HIGH] CVE-2013-3748: Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via ve Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via vectors related to Driver/IDM (iSCSI Data Mover).
nvd
CVE-2011-3543P3HIGHCVSS 7.8v5.112011-10-18
CVE-2011-3543 [HIGH] CVE-2011-3543: Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availabilit Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to iSCSI DataMover (IDM).
nvd
CVE-2012-3189P3HIGHCVSS 7.8v5.112012-10-17
CVE-2012-3189 [HIGH] CVE-2012-3189: Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability, r Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability, related to COMSTAR.
nvd
CVE-2012-3120P3HIGHCVSS 7.8v5.82012-07-17
CVE-2012-3120 [HIGH] CVE-2012-3120: Unspecified vulnerability in Oracle Sun Solaris 8 allows remote attackers to affect availability, re Unspecified vulnerability in Oracle Sun Solaris 8 allows remote attackers to affect availability, related to TCP/IP.
nvd
CVE-2010-4457P3HIGHCVSS 7.8v5.112011-01-19
CVE-2010-4457 [HIGH] CVE-2010-4457: Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availabilit Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to SMB and CIFS.
nvd
CVE-2012-0094P3HIGHCVSS 7.8v5.9v5.10+1 more2012-01-18
CVE-2012-0094 [HIGH] CVE-2012-0094: Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability, related to TCP/IP.
nvd
Sun Sunos vulnerabilities | cvebase