VendorsSunsolarisall versions
Vulnerabilities

Sun Solaris

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

545CVEs
CVE-1999-0189
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Published 2000-03-22 · Modified
7.5EPSS 0.012
CVE-1999-0300
nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
Published 1999-09-29 · Modified
7.5EPSS 0.011
CVE-2006-7034
SQL injection vulnerability in directory.php in Super Link Exchange Script 1.0 might allow remote attackers to execute arbitrary SQL queries via the cat parameter.
Published 2007-02-23 · Modified
7.5EPSS 0.011
CVE-2007-5365
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
Published 2007-10-11 · Modified
7.21 PoCEPSS 0.803
CVE-2002-0084
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.
Published 2002-03-07 · Modified
7.2EPSS 0.207
CVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Published 2003-04-02 · Modified
7.2EPSS 0.094
CVE-2003-0609
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.
Published 2003-08-01 · Modified
7.22 PoCEPSS 0.035
CVE-1999-1191
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
Published 2002-03-09 · Modified
7.22 PoCEPSS 0.019
CVE-2002-0572
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
Published 2002-06-11 · Modified
7.21 PoCEPSS 0.016
CVE-2001-1076
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
Published 2002-02-02 · Modified
7.21 PoCEPSS 0.014
CVE-2000-0471
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
Published 2000-10-13 · Modified
7.21 PoCEPSS 0.013
CVE-2001-1582
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.
Published 2007-09-23 · Modified
7.22 PoCEPSS 0.013
CVE-1999-0051
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
Published 1999-09-29 · Modified
7.23 PoCEPSS 0.013
CVE-2001-0422
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.013
CVE-2001-0423
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.
Published 2004-09-01 · Modified
7.21 PoCEPSS 0.013
CVE-2008-5689
tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.
Published 2008-12-19 · Modified
7.21 PoCEPSS 0.013
CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Published 1999-09-29 · Modified
7.25 PoCEPSS 0.012
CVE-2000-0317
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
Published 2000-05-18 · Modified
7.23 PoCEPSS 0.012
CVE-2001-0115
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.012
CVE-1999-0767
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
Published 2000-02-04 · Modified
7.25 PoCEPSS 0.012
CVE-2004-2686
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.
Published 2007-09-23 · Modified
7.21 PoCEPSS 0.012
CVE-2006-0745
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
Published 2006-03-21 · Modified
7.21 PoCEPSS 0.011
CVE-2000-0407
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
Published 2000-07-12 · Modified
7.22 PoCEPSS 0.011
CVE-2002-0158
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.
Published 2004-09-01 · Modified
7.21 PoCEPSS 0.011
CVE-2003-1055
Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.
Published 2005-02-08 · Modified
7.21 PoCEPSS 0.011
CVE-2005-2072
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
Published 2005-06-29 · Modified
7.22 PoCEPSS 0.010
CVE-2001-0401
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.010
CVE-2004-0360
Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.
Published 2004-03-18 · Modified
7.21 PoCEPSS 0.010
CVE-2001-0165
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.010
CVE-1999-0321
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
Published 1999-09-29 · Modified
7.22 PoCEPSS 0.009
CVE-2001-0426
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.009
CVE-2000-0337
Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
Published 2000-07-12 · Modified
7.21 PoCEPSS 0.009
CVE-2000-0316
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
Published 2000-07-12 · Modified
7.21 PoCEPSS 0.009
CVE-1999-1026
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.009
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0689
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0674
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0369
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0818
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.008
← Prev5 / 14Next →