VendorsSunsunosall versions
Vulnerabilities

Sun Sunos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

609CVEs
CVE-2006-0901
Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.
Published 2006-02-27 · Modified
7.2EPSS 0.004
CVE-2006-4306
Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 allows local users to execute arbitrary commands via unspecified vectors, involving the default Role-Based Access Control (RBAC) settings in the "File System Management" profile.
Published 2006-08-23 · Modified
7.2EPSS 0.004
CVE-2004-1767
The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.
Published 2005-03-10 · Modified
7.2EPSS 0.004
CVE-1999-0277
The WorkMan program can be used to overwrite any file to get root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2005-0816
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
Published 2005-03-20 · Modified
7.2EPSS 0.004
CVE-1999-1192
Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-2003-1057
Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2003-1082
Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2013-3750
Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/VM
Published 2013-07-17 · Modified
7.2EPSS 0.004
CVE-1999-1021
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-2003-0091
Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.
Published 2003-04-01 · Modified
7.2EPSS 0.004
CVE-1999-0334
In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0120
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-1419
Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-2003-1067
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-1999-1438
Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.
Published 2001-09-12 · Modified
7.2EPSS 0.004
CVE-1999-0840
Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
Published 2000-02-04 · Modified
7.2EPSS 0.004
CVE-1999-0136
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2002-0089
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.
Published 2002-03-07 · Modified
7.2EPSS 0.004
CVE-1999-0135
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0966
Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].
Published 2000-03-22 · Modified
7.2EPSS 0.004
CVE-1999-0339
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2003-0999
Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.
Published 2003-12-17 · Modified
7.2EPSS 0.004
CVE-2014-4282
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel/X86.
Published 2014-10-15 · Modified
7.2EPSS 0.004
CVE-2004-0496
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
Published 2004-07-06 · Modified
7.2EPSS 0.004
CVE-2003-0092
Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.
Published 2003-04-01 · Modified
7.2EPSS 0.004
CVE-2003-1068
Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-2014-6524
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.
Published 2015-01-21 · Modified
7.2EPSS 0.004
CVE-2001-0190
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-2002-0088
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
Published 2002-03-07 · Modified
7.2EPSS 0.004
CVE-2001-0470
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
Published 2001-05-24 · Modified
7.2EPSS 0.004
CVE-2001-0124
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-1999-1396
Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).
Published 2001-09-12 · Modified
7.2EPSS 0.004
CVE-1999-1197
TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-1999-1142
SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-2012-3204
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management.
Published 2012-10-17 · Modified
7.2EPSS 0.004
CVE-2002-2197
Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference.
Published 2005-11-16 · Modified
7.2EPSS 0.004
CVE-2012-3199
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Gnome Trusted Extension.
Published 2012-10-17 · Modified
7.2EPSS 0.004
CVE-2014-6473
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Framework.
Published 2014-10-15 · Modified
7.2EPSS 0.004
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
Published 1999-09-29 · Modified
7.2EPSS 0.004
← Prev6 / 16Next →