cbcvebase.

Sun Sunos vulnerabilities

537 known vulnerabilities affecting sun/sunos.

Total CVEs
537
CISA KEV
0
Public exploits
105
Exploited in wild
6
Severity breakdown
CRITICAL51HIGH177MEDIUM218LOW91

Vulnerabilities

Page 9 of 27
CVE-1999-0008P4CRITICALCVSS 10.0v5.3v5.4+2 more1998-06-08
CVE-1999-0008 [CRITICAL] CVE-1999-0008: Buffer overflow in NIS+, in Sun's rpc.nisd program. Buffer overflow in NIS+, in Sun's rpc.nisd program.
nvd
CVE-1999-0065P4HIGHCVSS 7.5v5.4v5.5+1 more1998-08-31
CVE-1999-0065 [HIGH] CVE-1999-0065: Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute comm Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
nvd
CVE-2013-3813P4MEDIUMCVSS 5.8v5.102013-07-17
CVE-2013-3813 [MEDIUM] CVE-2013-3813: Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality and Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality and integrity via vectors related to Libraries/PAM-Unix.
nvd
CVE-2002-0678P4HIGHCVSS 7.2v5.5.1v5.7+1 more2002-07-23
CVE-2002-0678 [HIGH] CVE-2002-0678: CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a syml CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
nvd
CVE-1999-0687P4HIGHCVSS 7.5v4.1.3u1v4.1.4+5 more1999-09-13
CVE-1999-0687 [HIGH] CVE-1999-0687: The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execut The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
nvd
CVE-1999-1584P4CRITICALCVSS 10.0v4.1.1v4.1.2+2 more1999-12-31
CVE-1999-1584 [CRITICAL] CVE-1999-1584: Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.
nvd
CVE-1999-1423P4LOWCVSS 2.1PoCv5.3v5.4+2 more1997-06-26
CVE-1999-1423 [LOW] CVE-1999-1423: ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping r ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
nvd
CVE-1999-0442P4LOWCVSS 2.1PoCv5.5v5.5.1+1 more1999-01-07
CVE-1999-0442 [LOW] CVE-1999-0442: Solaris ff.core allows local users to modify files. Solaris ff.core allows local users to modify files.
nvd
CVE-1999-0860P4LOWCVSS 2.1PoCv5.5.1v5.71999-12-01
CVE-1999-0860 [LOW] CVE-1999-0860: Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable a Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
nvd
CVE-1999-1506P4HIGHCVSS 7.5v3.5v4.0+4 more1990-01-29
CVE-1999-1506 [HIGH] CVE-1999-1506: Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to acce Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.
nvd
CVE-2012-3129P4MEDIUMCVSS 5.1v5.102012-07-17
CVE-2012-3129 [MEDIUM] CVE-2012-3129: Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, integrity, and availability, related to Gnome PDF viewer.
nvd
CVE-2001-1414P4HIGHCVSS 7.5v5.5.1v5.7+1 more2001-10-09
CVE-2001-1414 [HIGH] CVE-2001-1414: The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
nvd
CVE-2006-4306P4HIGHCVSS 7.2v5.82006-08-23
CVE-2006-4306 [HIGH] CVE-2006-4306: Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 allows local users to execute arbit Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 allows local users to execute arbitrary commands via unspecified vectors, involving the default Role-Based Access Control (RBAC) settings in the "File System Management" profile.
nvd
CVE-1999-0417P4LOWCVSS 2.1PoCv5.71999-03-09
CVE-1999-0417 [LOW] CVE-1999-0417: 64 bit Solaris 7 procfs allows local users to perform a denial of service. 64 bit Solaris 7 procfs allows local users to perform a denial of service.
nvd
CVE-2003-1081P4CRITICALCVSS 10.0v5.82003-09-09
CVE-2003-1081 [CRITICAL] CWE-264 CVE-2003-1081: Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .a Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.
nvd
CVE-1999-0302P4HIGHCVSS 7.5v5.3v5.5+1 more1998-09-01
CVE-1999-0302 [HIGH] CVE-1999-0302: SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server. SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
nvd
CVE-1999-0320P4CRITICALCVSS 9.3v4.1.3u1v4.1.4+4 more1998-03-01
CVE-1999-0320 [CRITICAL] CVE-1999-0320: SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files. SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
nvd
CVE-2014-6529P4MEDIUMCVSS 6.8v5.112014-10-15
CVE-2014-6529 [MEDIUM] CVE-2014-6529: Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hermon HCA PCIe driver.
nvd
CVE-1999-0859P4LOWCVSS 2.1PoCv5.5.1v5.71999-12-01
CVE-1999-0859 [LOW] CVE-1999-0859: Solaris arp allows local users to read files via the -f parameter, which lists lines in the file tha Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
nvd
CVE-2006-7028P4HIGHCVSS 7.8v5.7v5.82007-02-23
CVE-2006-7028 [HIGH] CVE-2006-7028: Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a denial of service (console hang) via a flood of small TCP/IP packets. NOTE: this issue has not been replicated by third parties. In addition, the cause is unknown, although it might be related to "jabber" and generation of a large amount of interrupts within the
nvd
Sun Sunos vulnerabilities | cvebase