VendorsSunsolaris2.6
Vulnerabilities

Sun Solaris 2.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

135CVEs
CVE-2001-1414
The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
Published 2005-02-08 · Modified
7.5EPSS 0.015
CVE-2003-1078
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
Published 2005-02-08 · Modified
7.5EPSS 0.013
CVE-2002-0084
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.
Published 2002-03-07 · Modified
7.2EPSS 0.207
CVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Published 2003-04-02 · Modified
7.2EPSS 0.094
CVE-2003-0609
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.
Published 2003-08-01 · Modified
7.22 PoCEPSS 0.035
CVE-2002-0572
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
Published 2002-06-11 · Modified
7.21 PoCEPSS 0.016
CVE-2001-1076
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
Published 2002-02-02 · Modified
7.21 PoCEPSS 0.014
CVE-2000-0471
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
Published 2000-10-13 · Modified
7.21 PoCEPSS 0.013
CVE-2001-0422
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.013
CVE-2000-0317
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
Published 2000-05-18 · Modified
7.23 PoCEPSS 0.012
CVE-2001-0115
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.012
CVE-1999-0767
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
Published 2000-02-04 · Modified
7.25 PoCEPSS 0.012
CVE-2004-2686
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.
Published 2007-09-23 · Modified
7.21 PoCEPSS 0.012
CVE-2000-0407
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
Published 2000-07-12 · Modified
7.22 PoCEPSS 0.011
CVE-2002-0158
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.
Published 2004-09-01 · Modified
7.21 PoCEPSS 0.011
CVE-2001-0401
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.010
CVE-2001-0426
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.009
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0689
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0674
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0773
Buffer overflow in Solaris lpset program allows local users to gain root access.
Published 2000-04-18 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0948
Buffer overflow in uum program for Canna input system allows local users to gain root privileges.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0949
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.007
CVE-2002-1296
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
Published 2004-09-01 · Modified
7.2EPSS 0.006
CVE-1999-0318
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.006
CVE-2002-1980
Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.
Published 2005-06-28 · Modified
7.2EPSS 0.005
CVE-1999-0055
Buffer overflows in Sun libnsl allow root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2004-1767
The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.
Published 2005-03-10 · Modified
7.2EPSS 0.004
CVE-2003-1057
Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2003-1082
Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2003-0091
Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.
Published 2003-04-01 · Modified
7.2EPSS 0.004
CVE-2003-1067
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2002-0089
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.
Published 2002-03-07 · Modified
7.2EPSS 0.004
CVE-1999-0339
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2003-0999
Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.
Published 2003-12-17 · Modified
7.2EPSS 0.004
CVE-2003-1068
Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2003-0092
Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.
Published 2003-04-01 · Modified
7.2EPSS 0.004
CVE-2002-0088
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
Published 2002-03-07 · Modified
7.2EPSS 0.004
CVE-2001-0124
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
Published 2001-05-07 · Modified
7.2EPSS 0.004
← Prev2 / 4Next →