VendorsSunsunos5.7
Vulnerabilities

Sun Sunos 5.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

151CVEs
CVE-2001-0548
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
Published 2004-09-01 · Modified
4.61 PoCEPSS 0.008
CVE-2004-1359
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.
Published 2005-01-19 · Modified
4.6EPSS 0.004
CVE-2005-3099
Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.
Published 2005-09-28 · Modified
4.6EPSS 0.004
CVE-2003-1062
Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.
Published 2005-02-08 · Modified
4.6EPSS 0.004
CVE-2004-2306
Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection.
Published 2005-08-16 · Modified
4.6EPSS 0.003
CVE-1999-0370
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
Published 2000-02-04 · Modified
4.6EPSS 0.003
CVE-2005-1124
Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.
Published 2005-04-16 · Modified
4.6EPSS 0.003
CVE-1999-1023
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.
Published 2001-09-12 · Modified
4.6EPSS 0.003
CVE-2003-0914
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
Published 2003-12-02 · Modified
4.3EPSS 0.032
CVE-2007-4310
The finger daemon (in.fingerd) in Sun Solaris 7 through 9 allows remote attackers to list all accounts that have certain nonstandard GECOS fields via a request composed of a single digit, as demonstrated by a "finger 9@host" command, a different vulnerability than CVE-2001-1503.
Published 2007-08-13 · Modified
4.3EPSS 0.011
CVE-2003-1058
The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.
Published 2005-02-08 · Modified
3.7EPSS 0.003
CVE-2005-4796
Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.
Published 2006-05-05 · Modified
3.6EPSS 0.003
CVE-2003-1071
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
Published 2005-02-08 · Modified
2.11 PoCEPSS 0.011
CVE-2001-1503
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
Published 2005-06-21 · Modified
2.1EPSS 0.008
CVE-1999-0442
Solaris ff.core allows local users to modify files.
Published 1999-09-29 · Modified
2.11 PoCEPSS 0.007
CVE-1999-0859
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
Published 2000-06-02 · Modified
2.11 PoCEPSS 0.006
CVE-1999-0860
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
Published 2000-02-04 · Modified
2.11 PoCEPSS 0.006
CVE-1999-0417
64 bit Solaris 7 procfs allows local users to perform a denial of service.
Published 1999-09-29 · Modified
2.11 PoCEPSS 0.006
CVE-2004-1360
Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.
Published 2005-01-19 · Modified
2.1EPSS 0.004
CVE-1999-0851
Denial of service in BIND named via naptr.
Published 2000-01-04 · Modified
2.1EPSS 0.004
CVE-2005-2032
Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.
Published 2005-06-21 · Modified
2.1EPSS 0.004
CVE-2004-0654
Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).
Published 2004-07-13 · Modified
2.1EPSS 0.004
CVE-2002-1586
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.
Published 2005-02-08 · Modified
2.1EPSS 0.003
CVE-2002-1587
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.
Published 2005-02-08 · Modified
2.1EPSS 0.003
CVE-2005-1518
Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.
Published 2005-05-11 · Modified
2.1EPSS 0.003
CVE-2003-1437
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
Published 2007-10-23 · Modified
2.1EPSS 0.002
CVE-2003-1073
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.
Published 2005-02-08 · Modified
1.21 PoCEPSS 0.007
CVE-2001-0095
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
Published 2001-09-18 · Modified
1.24 PoCEPSS 0.006
CVE-2003-0669
Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.
Published 2003-08-14 · Modified
1.2EPSS 0.003
CVE-2003-1080
Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.
Published 2005-02-08 · Modified
1.2EPSS 0.003
CVE-2003-1061
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.
Published 2005-02-08 · Modified
1.2EPSS 0.003
← Prev4 / 4