VendorsSunsolaris2.6
Vulnerabilities

Sun Solaris 2.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

135CVEs
CVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
Published 2002-06-25 · Modified
10.08 PoCEPSS 0.947
CVE-2003-0201
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
Published 2003-04-15 · Modified
10.012 PoCEPSS 0.845
CVE-2001-0236
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
Published 2002-03-09 · Modified
10.02 PoCEPSS 0.720
CVE-2003-0694
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Published 2003-09-18 · Modified
10.0EPSS 0.662
CVE-2001-0779
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
Published 2002-03-09 · Modified
10.01 PoCEPSS 0.622
CVE-2002-0391
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Published 2003-04-02 · Modified
10.0EPSS 0.581
CVE-2003-0161
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
Published 2003-04-01 · Modified
10.02 PoCEPSS 0.388
CVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Published 2002-03-09 · Modified
10.01 PoCEPSS 0.387
CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.290
CVE-1999-0003
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.246
CVE-2002-0679
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
Published 2003-04-02 · Modified
10.0EPSS 0.233
CVE-2002-0033
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.
Published 2003-04-02 · Modified
10.01 PoCEPSS 0.231
CVE-2003-0196
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
Published 2003-04-15 · Modified
10.0EPSS 0.228
CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Published 2001-01-22 · Modified
10.011 PoCEPSS 0.156
CVE-1999-0977
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
Published 2000-01-04 · Modified
10.05 PoCEPSS 0.126
CVE-1999-0696
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
Published 2000-06-02 · Modified
10.02 PoCEPSS 0.122
CVE-2002-1584
Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.
Published 2005-02-08 · Modified
10.0EPSS 0.057
CVE-2002-0796
Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
Published 2002-07-26 · Modified
10.0EPSS 0.044
CVE-1999-0186
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
Published 2000-02-04 · Modified
10.0EPSS 0.042
CVE-1999-0097
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
Published 1999-09-29 · Modified
10.0EPSS 0.040
CVE-1999-0254
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.
Published 2000-02-04 · Modified
10.0EPSS 0.039
CVE-1999-0008
Buffer overflow in NIS+, in Sun's rpc.nisd program.
Published 1999-09-29 · Modified
10.0EPSS 0.039
CVE-2001-0353
Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
Published 2001-09-18 · Modified
10.0EPSS 0.037
CVE-1999-0973
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
Published 2000-01-04 · Modified
10.01 PoCEPSS 0.035
CVE-2002-0797
Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
Published 2002-07-26 · Modified
10.0EPSS 0.033
CVE-1999-0974
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
Published 2000-01-04 · Modified
10.0EPSS 0.032
CVE-1999-0213
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
Published 2000-02-04 · Modified
10.0EPSS 0.019
CVE-1999-0502
A Unix account has a default, null, blank, or missing password.
Published 2000-02-04 · Modified
7.51 PoCEPSS 0.533
CVE-2002-1317
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
Published 2004-09-01 · Modified
7.51 PoCEPSS 0.240
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published 2003-03-21 · Modified
7.5EPSS 0.150
CVE-1999-0875
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
Published 2000-01-18 · Modified
7.51 PoCEPSS 0.102
CVE-2002-0573
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
Published 2003-04-02 · Modified
7.5EPSS 0.092
CVE-2002-0677
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Published 2002-07-12 · Modified
7.5EPSS 0.066
CVE-1999-0493
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
Published 2000-06-02 · Modified
7.51 PoCEPSS 0.043
CVE-1999-0065
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
Published 1999-09-29 · Modified
7.5EPSS 0.032
CVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Published 2004-09-01 · Modified
7.5EPSS 0.027
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
CVE-1999-1432
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
Published 2002-03-09 · Modified
7.51 PoCEPSS 0.021
CVE-1999-0302
SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
Published 1999-09-29 · Modified
7.5EPSS 0.015
CVE-2003-1063
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
Published 2005-02-08 · Modified
7.5EPSS 0.015
1 / 4Next →