VendorsSunsolaris2.5
Vulnerabilities

Sun Solaris 2.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-1999-0295
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
Published 1999-09-29 · Modified
7.2EPSS 0.003
CVE-2000-0055
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-1999-0513
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.709
CVE-1999-0024
DNS cache poisoning via BIND, by predictable query IDs.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-1999-0054
Sun's ftpd daemon can be subjected to a denial of service.
Published 1999-09-29 · Modified
5.0EPSS 0.014
CVE-2001-0565
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
Published 2002-03-09 · Modified
4.62 PoCEPSS 0.013
CVE-1999-0125
Buffer overflow in SGI IRIX mailx program.
Published 1999-09-29 · Modified
4.62 PoCEPSS 0.011
CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Published 1999-09-29 · Modified
4.6EPSS 0.006
CVE-1999-0786
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
Published 2000-03-22 · Modified
4.61 PoCEPSS 0.006
CVE-1999-0303
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Published 1999-09-29 · Modified
4.6EPSS 0.003
CVE-1999-0676
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Published 2000-04-18 · Modified
4.6EPSS 0.003
CVE-2005-4796
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.
Published 2006-05-05 · Modified
3.6EPSS 0.003
CVE-1999-1423
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
Published 2002-03-09 · Modified
2.11 PoCEPSS 0.009
CVE-1999-1402
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
Published 2002-03-09 · Modified
2.11 PoCEPSS 0.008
CVE-2001-1503
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
Published 2005-06-21 · Modified
2.1EPSS 0.008
CVE-1999-0442
Solaris ff.core allows local users to modify files.
Published 1999-09-29 · Modified
2.11 PoCEPSS 0.007
← Prev2 / 2