VendorsSunsolaris2.5.1
Vulnerabilities

Sun Solaris 2.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

75CVEs
CVE-1999-0301
Buffer overflow in SunOS/Solaris ps command.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-2002-1980
Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.
Published 2005-06-28 · Modified
7.2EPSS 0.005
CVE-1999-0055
Buffer overflows in Sun libnsl allow root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0135
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0339
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0139
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0295
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
Published 1999-09-29 · Modified
7.2EPSS 0.003
CVE-2000-0055
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-1999-0513
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.709
CVE-2003-0027
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.
Published 2004-09-01 · Modified
5.0EPSS 0.257
CVE-1999-0024
DNS cache poisoning via BIND, by predictable query IDs.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-2003-1079
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.
Published 2005-02-08 · Modified
5.0EPSS 0.024
CVE-1999-0908
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
Published 2000-03-22 · Modified
5.01 PoCEPSS 0.022
CVE-2002-1228
Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.
Published 2002-10-21 · Modified
5.0EPSS 0.018
CVE-1999-0054
Sun's ftpd daemon can be subjected to a denial of service.
Published 1999-09-29 · Modified
5.0EPSS 0.014
CVE-2002-2203
Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.
Published 2005-11-16 · Modified
4.9EPSS 0.003
CVE-2001-0565
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
Published 2002-03-09 · Modified
4.62 PoCEPSS 0.013
CVE-1999-0125
Buffer overflow in SGI IRIX mailx program.
Published 1999-09-29 · Modified
4.62 PoCEPSS 0.011
CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Published 1999-09-29 · Modified
4.6EPSS 0.006
CVE-1999-0786
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
Published 2000-03-22 · Modified
4.61 PoCEPSS 0.006
CVE-1999-0370
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
Published 2000-02-04 · Modified
4.6EPSS 0.003
CVE-1999-0676
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Published 2000-04-18 · Modified
4.6EPSS 0.003
CVE-2003-1575
VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.
Published 2010-01-28 · Modified
4.6EPSS 0.003
CVE-2005-4796
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.
Published 2006-05-05 · Modified
3.6EPSS 0.003
CVE-2003-1071
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
Published 2005-02-08 · Modified
2.11 PoCEPSS 0.011
CVE-1999-1423
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
Published 2002-03-09 · Modified
2.11 PoCEPSS 0.009
CVE-1999-1402
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
Published 2002-03-09 · Modified
2.11 PoCEPSS 0.008
CVE-2001-1503
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
Published 2005-06-21 · Modified
2.1EPSS 0.008
CVE-1999-0442
Solaris ff.core allows local users to modify files.
Published 1999-09-29 · Modified
2.11 PoCEPSS 0.007
CVE-1999-0859
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
Published 2000-06-02 · Modified
2.11 PoCEPSS 0.006
CVE-1999-0860
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
Published 2000-02-04 · Modified
2.11 PoCEPSS 0.006
CVE-2002-1586
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.
Published 2005-02-08 · Modified
2.1EPSS 0.003
CVE-2002-1587
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.
Published 2005-02-08 · Modified
2.1EPSS 0.003
← Prev2 / 2