VendorsSunsunos5.5.1
Vulnerabilities

Sun Sunos 5.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

112CVEs
CVE-1999-0300
nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
Published 1999-09-29 · Modified
7.5EPSS 0.011
CVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Published 2003-04-02 · Modified
7.2EPSS 0.094
CVE-2002-0572
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
Published 2002-06-11 · Modified
7.21 PoCEPSS 0.016
CVE-2001-1076
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.
Published 2002-02-02 · Modified
7.21 PoCEPSS 0.014
CVE-2000-0471
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
Published 2000-10-13 · Modified
7.21 PoCEPSS 0.013
CVE-1999-0051
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
Published 1999-09-29 · Modified
7.23 PoCEPSS 0.013
CVE-2001-0422
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.013
CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Published 1999-09-29 · Modified
7.25 PoCEPSS 0.012
CVE-2001-0115
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.012
CVE-2000-0949
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
Published 2001-01-22 · Modified
7.24 PoCEPSS 0.012
CVE-2001-0401
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.010
CVE-1999-1371
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.010
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-1158
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.
Published 2001-09-12 · Modified
7.22 PoCEPSS 0.008
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0689
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0674
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0369
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0109
Buffer overflow in ffbconfig in Solaris 2.5.1.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0301
Buffer overflow in SunOS/Solaris ps command.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0023
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0033
Command execution in Sun systems via buffer overflow in the at program.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-2002-1296
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
Published 2004-09-01 · Modified
7.2EPSS 0.006
CVE-1999-0318
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.006
CVE-2002-1980
Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.
Published 2005-06-28 · Modified
7.2EPSS 0.005
CVE-1999-0055
Buffer overflows in Sun libnsl allow root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2003-0091
Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.
Published 2003-04-01 · Modified
7.2EPSS 0.004
CVE-1999-0136
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2002-0089
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.
Published 2002-03-07 · Modified
7.2EPSS 0.004
CVE-1999-0135
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0339
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2003-0092
Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.
Published 2003-04-01 · Modified
7.2EPSS 0.004
CVE-2001-0124
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-2001-0190
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0056
Buffer overflow in Sun's ping program can give root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2002-1871
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Published 2005-06-28 · Modified
7.2EPSS 0.004
CVE-1999-0134
vold in Solaris 2.x allows local users to gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2003-1059
Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.
Published 2005-02-08 · Modified
7.2EPSS 0.003
← Prev2 / 3Next →