VendorsSunsunosall versions
Vulnerabilities

Sun Sunos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

609CVEs
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0296
Solaris volrmmount program allows attackers to read any file.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2007-2529
Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.
Published 2007-05-09 · Modified
7.2EPSS 0.004
CVE-2008-3450
Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.
Published 2008-08-04 · Modified
7.2EPSS 0.004
CVE-1999-0056
Buffer overflow in Sun's ping program can give root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2003-1024
Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.
Published 2004-01-06 · Modified
7.2EPSS 0.004
CVE-1999-1586
loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.
Published 2005-08-30 · Modified
7.2EPSS 0.004
CVE-2004-1353
Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.
Published 2005-01-19 · Modified
7.2EPSS 0.004
CVE-2014-6521
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via vectors related to CDE - Power Management Utility.
Published 2015-01-21 · Modified
7.2EPSS 0.004
CVE-2002-1871
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
Published 2005-06-28 · Modified
7.2EPSS 0.004
CVE-1999-1585
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
Published 2005-08-30 · Modified
7.2EPSS 0.004
CVE-1999-0134
vold in Solaris 2.x allows local users to gain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-1999-0139
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Published 1999-09-29 · Modified
7.2EPSS 0.004
CVE-2002-1590
The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
Published 2005-02-08 · Modified
7.2EPSS 0.004
CVE-1999-1080
rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.
Published 2002-06-25 · Modified
7.2EPSS 0.003
CVE-2014-6510
Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility.
Published 2015-01-21 · Modified
7.2EPSS 0.003
CVE-1999-1212
Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.003
CVE-1999-1211
Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.
Published 2001-09-12 · Modified
7.2EPSS 0.003
CVE-2006-4307
Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.
Published 2006-08-23 · Modified
7.2EPSS 0.003
CVE-2003-1056
The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
Published 2005-02-08 · Modified
7.2EPSS 0.003
CVE-2003-1059
Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.
Published 2005-02-08 · Modified
7.2EPSS 0.003
CVE-2003-1076
Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.
Published 2005-02-08 · Modified
7.2EPSS 0.003
CVE-1999-0295
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
Published 1999-09-29 · Modified
7.2EPSS 0.003
CVE-2007-0470
Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.
Published 2007-01-24 · Modified
7.2EPSS 0.003
CVE-1999-0952
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-2000-0055
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
Published 2000-02-04 · Modified
7.2EPSS 0.003
CVE-2005-4795
Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.
Published 2006-05-05 · Modified
7.2EPSS 0.003
CVE-2012-1796
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
Published 2012-03-20 · Modified
7.2EPSS 0.003
CVE-2007-3880
Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.
Published 2007-11-14 · Modified
7.2EPSS 0.003
CVE-1999-1318
/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.
Published 2002-03-09 · Modified
7.2EPSS 0.003
CVE-2011-2285
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Installer.
Published 2011-07-21 · Modified
7.2EPSS 0.003
CVE-2009-4191
Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated by the vd_sol_local module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
Published 2009-12-03 · Modified
7.2EPSS 0.003
CVE-2008-3666
Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.
Published 2008-08-13 · Modified
7.1EPSS 0.017
CVE-2012-3125
Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows remote attackers to affect availability, related to TCP/IP.
Published 2012-07-17 · Modified
7.1EPSS 0.017
CVE-2011-0902
Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.
Published 2011-02-07 · Modified
6.91 PoCEPSS 0.015
CVE-2007-0503
Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.
Published 2007-01-25 · Modified
6.9EPSS 0.004
CVE-2012-3187
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.
Published 2012-10-17 · Modified
6.9EPSS 0.003
CVE-2007-3717
rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.
Published 2007-07-12 · Modified
6.9EPSS 0.003
CVE-2014-4225
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Patch installation scripts.
Published 2014-07-17 · Modified
6.9EPSS 0.003
CVE-2011-3337
eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows local users to gain privileges via a Trojan horse gauntlet program in an arbitrary directory under /usr/local/.
Published 2012-01-04 · Modified
6.9EPSS 0.003
← Prev7 / 16Next →