VendorsSunsolaris2.6
Vulnerabilities

Sun Solaris 2.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

135CVEs
CVE-2001-0190
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0296
Solaris volrmmount program allows attackers to read any file.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2002-1871
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Published 2005-06-28 · Modified
7.2EPSS 0.004
CVE-1999-1027
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
Published 2002-03-09 · Modified
7.2EPSS 0.003
CVE-2003-1056
The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
Published 2005-02-08 · Modified
7.2EPSS 0.003
CVE-2003-1059
Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.
Published 2005-02-08 · Modified
7.2EPSS 0.003
CVE-1999-0952
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-2000-0055
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-2001-0421
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.
Published 2001-05-24 · Modified
6.41 PoCEPSS 0.062
CVE-1999-0513
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Published 1999-09-29 · Modified
5.01 PoCEPSS 0.709
CVE-2003-0027
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.
Published 2004-09-01 · Modified
5.0EPSS 0.257
CVE-1999-0024
DNS cache poisoning via BIND, by predictable query IDs.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-2003-1066
Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.
Published 2005-02-08 · Modified
5.0EPSS 0.033
CVE-2002-1345
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
Published 2002-12-17 · Modified
5.0EPSS 0.028
CVE-2004-1393
Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).
Published 2005-02-08 · Modified
5.0EPSS 0.026
CVE-2003-1079
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.
Published 2005-02-08 · Modified
5.0EPSS 0.024
CVE-1999-0908
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
Published 2000-03-22 · Modified
5.01 PoCEPSS 0.022
CVE-2002-0085
cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.
Published 2002-03-07 · Modified
5.0EPSS 0.018
CVE-2003-1075
Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.
Published 2005-02-08 · Modified
5.0EPSS 0.016
CVE-2003-1069
The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).
Published 2005-02-08 · Modified
5.0EPSS 0.016
CVE-2003-1070
Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).
Published 2005-02-08 · Modified
5.0EPSS 0.016
CVE-1999-0054
Sun's ftpd daemon can be subjected to a denial of service.
Published 1999-09-29 · Modified
5.0EPSS 0.014
CVE-2002-2203
Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.
Published 2005-11-16 · Modified
4.9EPSS 0.003
CVE-2001-0565
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
Published 2002-03-09 · Modified
4.62 PoCEPSS 0.013
CVE-1999-0125
Buffer overflow in SGI IRIX mailx program.
Published 1999-09-29 · Modified
4.62 PoCEPSS 0.011
CVE-2001-0548
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
Published 2004-09-01 · Modified
4.61 PoCEPSS 0.008
CVE-1999-0786
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
Published 2000-03-22 · Modified
4.61 PoCEPSS 0.006
CVE-2004-1359
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.
Published 2005-01-19 · Modified
4.6EPSS 0.004
CVE-2003-1062
Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.
Published 2005-02-08 · Modified
4.6EPSS 0.004
CVE-1999-1025
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
Published 2001-09-12 · Modified
4.6EPSS 0.003
CVE-1999-0370
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
Published 2000-02-04 · Modified
4.6EPSS 0.003
CVE-1999-0676
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Published 2000-04-18 · Modified
4.6EPSS 0.003
CVE-2003-1575
VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.
Published 2010-01-28 · Modified
4.6EPSS 0.003
CVE-2004-2766
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
Published 2010-01-28 · Modified
4.3EPSS 0.014
CVE-2004-2765
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.
Published 2010-01-28 · Modified
4.3EPSS 0.013
CVE-2003-1563
Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.
Published 2008-08-18 · Modified
4.0EPSS 0.003
CVE-2003-1058
The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.
Published 2005-02-08 · Modified
3.7EPSS 0.003
CVE-2005-4796
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.
Published 2006-05-05 · Modified
3.6EPSS 0.003
← Prev3 / 4Next →