VendorsSunsolarisall versions
Vulnerabilities

Sun Solaris

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

545CVEs
CVE-2009-0923
Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.
Published 2009-03-17 · Modified
7.8EPSS 0.024
CVE-2007-5462
Unspecified vulnerability in the Sun Solaris RPC services library (librpcsvc) on Solaris 8 through 10 allows remote attackers to cause a denial of service (mountd crash) via unspecified packets to a server that exports many filesystems, and allows local users to cause a denial of service (automountd crash) via unspecified requests to mount filesystems from a server that exports many filesystems.
Published 2007-10-15 · Modified
7.8EPSS 0.022
CVE-2009-2486
Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.
Published 2009-07-16 · Modified
7.8EPSS 0.020
CVE-2008-2089
Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.
Published 2008-05-06 · Modified
7.8EPSS 0.020
CVE-2008-2090
Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.
Published 2008-05-06 · Modified
7.8EPSS 0.020
CVE-2007-3626
Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.
Published 2007-07-09 · Modified
7.8EPSS 0.019
CVE-2008-2707
Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (network connectivity loss) via unknown vectors.
Published 2008-06-16 · Modified
7.8EPSS 0.019
CVE-2009-2137
Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-dependent attackers to cause a denial of service (memory consumption) via unspecified vectors related to a large keylen value.
Published 2009-06-19 · Modified
7.8EPSS 0.018
CVE-2006-7028
Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a denial of service (console hang) via a flood of small TCP/IP packets. NOTE: this issue has not been replicated by third parties. In addition, the cause is unknown, although it might be related to "jabber" and generation of a large amount of interrupts within the console, or a hardware error.
Published 2007-02-23 · Modified
7.8EPSS 0.017
CVE-2006-3781
Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via unspecified vectors involving the event port API.
Published 2006-07-21 · Modified
7.8EPSS 0.017
CVE-1999-0022
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Published 1999-09-29 · Modified
7.8EPSS 0.005
CVE-2007-4938
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
Published 2007-09-18 · Modified
7.61 PoCEPSS 0.160
CVE-2007-6180
Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via unspecified vectors.
Published 2007-11-30 · Modified
7.6EPSS 0.007
CVE-1999-0502
A Unix account has a default, null, blank, or missing password.
Published 2000-02-04 · Modified
7.51 PoCEPSS 0.533
CVE-2002-1317
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
Published 2004-09-01 · Modified
7.51 PoCEPSS 0.240
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published 2003-03-21 · Modified
7.5EPSS 0.150
CVE-1999-0875
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
Published 2000-01-18 · Modified
7.51 PoCEPSS 0.102
CVE-2002-0573
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
Published 2003-04-02 · Modified
7.5EPSS 0.092
CVE-2007-1043
Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php.
Published 2007-02-21 · Modified
7.51 PoCEPSS 0.083
CVE-1999-0057
Vacation program allows command execution by remote users through a sendmail command.
Published 1999-09-29 · Modified
7.5EPSS 0.082
CVE-2004-1082
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
Published 2005-04-21 · Modified
7.5EPSS 0.076
CVE-1999-0185
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
Published 1999-09-29 · Modified
7.5EPSS 0.073
CVE-2002-0677
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Published 2002-07-12 · Modified
7.5EPSS 0.066
CVE-2004-1307
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
Published 2005-05-04 · Modified
7.5EPSS 0.063
CVE-2007-1681
Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.
Published 2007-04-19 · Modified
7.5EPSS 0.046
CVE-1999-0493
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
Published 2000-06-02 · Modified
7.51 PoCEPSS 0.043
CVE-1999-0065
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
Published 1999-09-29 · Modified
7.5EPSS 0.032
CVE-2005-2870
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
Published 2005-09-08 · Modified
7.5EPSS 0.028
CVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Published 2004-09-01 · Modified
7.5EPSS 0.027
CVE-2008-5422
Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors.
Published 2008-12-11 · Modified
7.5EPSS 0.026
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
CVE-1999-0833
Buffer overflow in BIND 8.2 via NXT records.
Published 2000-01-04 · Modified
7.5EPSS 0.021
CVE-1999-0795
The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.
Published 2000-02-04 · Modified
7.5EPSS 0.021
CVE-1999-1432
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
Published 2002-03-09 · Modified
7.51 PoCEPSS 0.021
CVE-1999-0302
SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
Published 1999-09-29 · Modified
7.5EPSS 0.015
CVE-2003-1063
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
Published 2005-02-08 · Modified
7.5EPSS 0.015
CVE-2001-1414
The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
Published 2005-02-08 · Modified
7.5EPSS 0.015
CVE-2005-0248
The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
Published 2005-02-08 · Modified
7.5EPSS 0.014
CVE-2007-1945
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.
Published 2007-04-11 · Modified
7.5EPSS 0.014
CVE-2003-1078
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
Published 2005-02-08 · Modified
7.5EPSS 0.013
← Prev4 / 14Next →