VendorsSunsunosall versions
Vulnerabilities

Sun Sunos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

609CVEs
CVE-2003-1055
Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.
Published 2005-02-08 · Modified
7.21 PoCEPSS 0.011
CVE-2005-2072
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
Published 2005-06-29 · Modified
7.22 PoCEPSS 0.010
CVE-1999-0032
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
Published 1999-09-29 · Modified
7.22 PoCEPSS 0.010
CVE-2001-0401
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.010
CVE-1999-1371
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.010
CVE-2004-0360
Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.
Published 2004-03-18 · Modified
7.21 PoCEPSS 0.010
CVE-2001-0165
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
Published 2001-05-07 · Modified
7.21 PoCEPSS 0.010
CVE-2001-0652
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.
Published 2002-03-09 · Modified
7.22 PoCEPSS 0.009
CVE-2001-0426
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.009
CVE-2000-0316
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
Published 2000-07-12 · Modified
7.21 PoCEPSS 0.009
CVE-2000-0337
Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
Published 2000-07-12 · Modified
7.21 PoCEPSS 0.009
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-1158
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.
Published 2001-09-12 · Modified
7.22 PoCEPSS 0.008
CVE-1999-0691
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0689
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0674
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0841
Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0369
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0818
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0109
Buffer overflow in ffbconfig in Solaris 2.5.1.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-2000-0118
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
Published 2000-02-08 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0806
Buffer overflow in Solaris dtprintinfo program.
Published 2000-03-22 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0301
Buffer overflow in SunOS/Solaris ps command.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0023
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0773
Buffer overflow in Solaris lpset program allows local users to gain root access.
Published 2000-04-18 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0948
Buffer overflow in uum program for Canna input system allows local users to gain root privileges.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0949
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.
Published 2000-02-04 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0410
The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.007
CVE-2001-0403
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
Published 2001-05-24 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0033
Command execution in Sun systems via buffer overflow in the at program.
Published 2000-02-04 · Modified
7.2EPSS 0.006
CVE-2002-1296
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
Published 2004-09-01 · Modified
7.2EPSS 0.006
CVE-1999-0318
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.006
CVE-2008-2710
Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory. NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.
Published 2008-06-16 · Modified
7.2EPSS 0.006
CVE-1999-1507
Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-2004-0780
Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.
Published 2006-01-10 · Modified
7.2EPSS 0.005
CVE-2004-1352
Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.
Published 2005-01-19 · Modified
7.2EPSS 0.005
CVE-2006-4319
Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307.
Published 2006-08-24 · Modified
7.2EPSS 0.005
CVE-2002-1980
Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.
Published 2005-06-28 · Modified
7.2EPSS 0.005
CVE-2001-0699
Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.
Published 2002-03-09 · Modified
7.2EPSS 0.005
CVE-1999-0055
Buffer overflows in Sun libnsl allow root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
← Prev5 / 16Next →