VendorsSunsolaris2.5
Vulnerabilities

Sun Solaris 2.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
Published 2002-06-25 · Modified
10.08 PoCEPSS 0.947
CVE-2003-0161
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
Published 2003-04-01 · Modified
10.02 PoCEPSS 0.388
CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.290
CVE-1999-0977
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
Published 2000-01-04 · Modified
10.05 PoCEPSS 0.126
CVE-1999-0696
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
Published 2000-06-02 · Modified
10.02 PoCEPSS 0.122
CVE-1999-0018
Buffer overflow in statd allows root privileges.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.105
CVE-1999-1588
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.
Published 2006-04-21 · Modified
10.01 PoCEPSS 0.099
CVE-1999-0210
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
Published 2000-06-02 · Modified
10.01 PoCEPSS 0.062
CVE-1999-0241
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
Published 2000-02-04 · Modified
10.0EPSS 0.043
CVE-1999-0097
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
Published 1999-09-29 · Modified
10.0EPSS 0.040
CVE-1999-0973
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
Published 2000-01-04 · Modified
10.01 PoCEPSS 0.035
CVE-1999-0974
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
Published 2000-01-04 · Modified
10.0EPSS 0.032
CVE-1999-0320
SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
Published 1999-09-29 · Modified
9.3EPSS 0.013
CVE-1999-0038
Buffer overflow in xlock program allows local users to execute commands as root.
Published 1999-09-29 · Modified
8.42 PoCEPSS 0.013
CVE-1999-0185
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
Published 1999-09-29 · Modified
7.5EPSS 0.073
CVE-1999-0493
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
Published 2000-06-02 · Modified
7.51 PoCEPSS 0.043
CVE-1999-0065
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
Published 1999-09-29 · Modified
7.5EPSS 0.032
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
CVE-1999-1432
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
Published 2002-03-09 · Modified
7.51 PoCEPSS 0.021
CVE-1999-0189
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Published 2000-03-22 · Modified
7.5EPSS 0.012
CVE-1999-0300
nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
Published 1999-09-29 · Modified
7.5EPSS 0.011
CVE-1999-1191
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
Published 2002-03-09 · Modified
7.22 PoCEPSS 0.019
CVE-2001-1076
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
Published 2002-02-02 · Modified
7.21 PoCEPSS 0.014
CVE-2000-0471
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
Published 2000-10-13 · Modified
7.21 PoCEPSS 0.013
CVE-1999-0051
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
Published 1999-09-29 · Modified
7.23 PoCEPSS 0.013
CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Published 1999-09-29 · Modified
7.25 PoCEPSS 0.012
CVE-2001-0115
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.012
CVE-1999-1026
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.009
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0689
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0674
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0369
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0109
Buffer overflow in ffbconfig in Solaris 2.5.1.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0301
Buffer overflow in SunOS/Solaris ps command.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0055
Buffer overflows in Sun libnsl allow root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0135
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0339
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0139
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
1 / 2Next →