VendorsSunsunosall versions
Vulnerabilities

Sun Sunos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

609CVEs
CVE-1999-0125
Buffer overflow in SGI IRIX mailx program.
Published 1999-09-29 · Modified
4.62 PoCEPSS 0.011
CVE-1999-1014
Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
Published 2002-03-09 · Modified
4.61 PoCEPSS 0.010
CVE-2001-0594
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.
Published 2002-03-09 · Modified
4.62 PoCEPSS 0.010
CVE-2001-0548
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
Published 2004-09-01 · Modified
4.61 PoCEPSS 0.008
CVE-1999-1413
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
Published 2001-09-12 · Modified
4.61 PoCEPSS 0.007
CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Published 1999-09-29 · Modified
4.6EPSS 0.006
CVE-1999-0786
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
Published 2000-03-22 · Modified
4.61 PoCEPSS 0.006
CVE-2002-1323
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
Published 2004-09-01 · Modified
4.6EPSS 0.005
CVE-2004-0800
Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.
Published 2004-08-25 · Modified
4.6EPSS 0.004
CVE-2013-5821
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via vectors related to RPC.
Published 2014-01-15 · Modified
4.6EPSS 0.004
CVE-2001-1555
pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.
Published 2005-07-14 · Modified
4.6EPSS 0.004
CVE-2004-1359
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.
Published 2005-01-19 · Modified
4.6EPSS 0.004
CVE-2005-3099
Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.
Published 2005-09-28 · Modified
4.6EPSS 0.004
CVE-1999-0167
In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.
Published 1999-09-29 · Modified
4.6EPSS 0.004
CVE-1999-0143
Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.
Published 1999-09-29 · Modified
4.6EPSS 0.004
CVE-1999-1122
Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.
Published 2002-03-09 · Modified
4.6EPSS 0.004
CVE-2006-0161
Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.
Published 2006-01-10 · Modified
4.6EPSS 0.004
CVE-2003-1062
Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.
Published 2005-02-08 · Modified
4.6EPSS 0.004
CVE-2014-4280
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4284.
Published 2014-10-15 · Modified
4.6EPSS 0.004
CVE-2011-2258
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rksh.
Published 2011-07-20 · Modified
4.6EPSS 0.004
CVE-2014-0421
Unspecified vulnerability in Oracle Solaris 10, when running on the SPARC64-X Platform, allows local users to affect confidentiality, integrity, and availability via unknown vectors.
Published 2014-04-15 · Modified
4.6EPSS 0.004
CVE-2014-0442
Unspecified vulnerability in Oracle Solaris 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Print Filter Utility.
Published 2014-04-15 · Modified
4.6EPSS 0.004
CVE-2004-2306
Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection.
Published 2005-08-16 · Modified
4.6EPSS 0.003
CVE-1999-1025
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
Published 2001-09-12 · Modified
4.6EPSS 0.003
CVE-1999-0303
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Published 1999-09-29 · Modified
4.6EPSS 0.003
CVE-2013-0407
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework.
Published 2013-01-17 · Modified
4.6EPSS 0.003
CVE-2012-3211
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/System Call.
Published 2012-10-17 · Modified
4.6EPSS 0.003
CVE-2004-1394
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
Published 2005-02-08 · Modified
4.6EPSS 0.003
CVE-2010-4446
Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to RDS and Kernel/InfiniBand.
Published 2011-01-19 · Modified
4.6EPSS 0.003
CVE-1999-0263
Solaris SUNWadmap can be exploited to obtain root access.
Published 1999-09-29 · Modified
4.6EPSS 0.003
CVE-1999-0370
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
Published 2000-02-04 · Modified
4.6EPSS 0.003
CVE-2002-1763
The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.
Published 2005-06-21 · Modified
4.6EPSS 0.003
CVE-2005-1124
Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.
Published 2005-04-16 · Modified
4.6EPSS 0.003
CVE-1999-1023
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.
Published 2001-09-12 · Modified
4.6EPSS 0.003
CVE-1999-0676
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Published 2000-04-18 · Modified
4.6EPSS 0.003
CVE-2010-4459
Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to SCTP and Kernel/sockfs.
Published 2011-01-19 · Modified
4.6EPSS 0.003
CVE-2013-0413
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Remote Execution Service.
Published 2013-04-17 · Modified
4.4EPSS 0.006
CVE-2012-5095
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to inetd.
Published 2012-10-17 · Modified
4.4EPSS 0.004
CVE-2012-1750
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to mailx.
Published 2012-07-17 · Modified
4.4EPSS 0.003
CVE-2014-4284
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.
Published 2014-10-15 · Modified
4.4EPSS 0.003
← Prev12 / 16Next →