cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 8 of 27
CVE-1999-1587P4LOWCVSS 2.1PoCv5.81999-12-31
CVE-1999-1587 [LOW] CVE-1999-1587: /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.
nvd
CVE-1999-0786P4MEDIUMCVSS 4.6PoCv5.4v5.5+1 more1999-09-22
CVE-1999-0786 [MEDIUM] CVE-1999-0786: The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE envir The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
nvd
CVE-2012-1694P4MEDIUMCVSS 6.4v5.102012-05-03
CVE-2012-1694 [MEDIUM] CVE-2012-1694: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl.
nvd
CVE-2013-0405P4MEDIUMCVSS 6.4v5.8v5.9+2 more2013-04-17
CVE-2013-0405 [MEDIUM] CVE-2013-0405: Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows remote attackers to affect c Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality and integrity via vectors related to NFS client mounts and IPv6.
nvd
CVE-2003-1071P4LOWCVSS 2.1PoCv5.5.1v5.7+1 more2003-01-03
CVE-2003-1071 [LOW] CVE-2003-1071: rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on u rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
nvd
CVE-1999-0185P4HIGHCVSS 7.5v4.1.3u1v4.1.4+4 more1997-10-01
CVE-1999-0185 [HIGH] CVE-1999-0185: In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
nvd
CVE-2012-3125P4HIGHCVSS 7.1v5.8v5.9+1 more2012-07-17
CVE-2012-3125 [HIGH] CVE-2012-3125: Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows remote attackers to affect avail Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows remote attackers to affect availability, related to TCP/IP.
nvd
CVE-1999-1413P4MEDIUMCVSS 4.6PoCv5.41996-08-03
CVE-1999-1413 [MEDIUM] CVE-1999-1413: Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
nvd
CVE-1999-1402P4LOWCVSS 2.1PoCv4.0v5.0+2 more1997-05-17
CVE-1999-1402 [LOW] CVE-1999-1402: The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
nvd
CVE-2007-3223P4HIGHCVSS 7.8v5.102007-06-14
CVE-2007-3223 [HIGH] CVE-2007-3223: Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attacker Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.
nvd
CVE-2002-0884P4HIGHCVSS 7.5v5.7v5.82002-10-04
CVE-2002-0884 [HIGH] CVE-2002-0884: Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Ope Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error.
nvd
CVE-2005-0248P4HIGHCVSS 7.5v5.82005-05-02
CVE-2005-0248 [HIGH] CVE-2005-0248: The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are c The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
nvd
CVE-2008-2710P4HIGHCVSS 7.2≤ -2008-06-16
CVE-2008-2710 [HIGH] CWE-189 CVE-2008-2710: Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/i Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an o
nvd
CVE-2008-2121P4HIGHCVSS 7.8v5.8v5.9+1 more2008-05-09
CVE-2008-2121 [HIGH] CWE-16 CVE-2008-2121: The TCP implementation in Sun Solaris 8, 9, and 10 allows remote attackers to cause a denial of serv The TCP implementation in Sun Solaris 8, 9, and 10 allows remote attackers to cause a denial of service (CPU consumption and new connection timeouts) via a TCP SYN flood attack.
nvd
CVE-2008-2946P4HIGHCVSS 7.8v5.8v5.9+1 more2008-06-30
CVE-2008-2946 [HIGH] CWE-399 CVE-2008-2946: The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 t The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.
nvd
CVE-2002-0885P4HIGHCVSS 7.5v5.7v5.82002-10-04
CVE-2002-0885 [HIGH] CVE-2002-0885: Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.
nvd
CVE-2003-0064P4HIGHCVSS 7.5v5.5.1v5.7+1 more2003-03-03
CVE-2003-0064 [HIGH] CVE-2003-0064: The dtterm terminal emulator allows attackers to modify the window title via a certain character esc The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
nvd
CVE-2001-0095P4LOWCVSS 1.2PoCv5.7v5.82001-02-12
CVE-2001-0095 [LOW] CVE-2001-0095: catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack o catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
nvd
CVE-2005-0488P4MEDIUMCVSS 5.0v5.92005-06-14
CVE-2005-0488 [MEDIUM] CVE-2005-0488: Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malic Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
nvd
CVE-2006-5073P4HIGHCVSS 7.8v5.82006-09-29
CVE-2006-5073 [HIGH] CVE-2006-5073: Unspecified vulnerability in Sun Solaris 8, 9 and 10 allows remote attackers to cause a denial of se Unspecified vulnerability in Sun Solaris 8, 9 and 10 allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets, a different vulnerability than CVE-2006-5013.
nvd
Sun Sunos vulnerabilities | cvebase