VendorsSunsunos5.11
Vulnerabilities

Sun Sunos 5.11

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

126CVEs
CVE-2007-0882
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.
Published 2007-02-12 · Modified
10.03 PoCEPSS 0.980
CVE-2011-3508
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect confidentiality, integrity, and availability, related to LDAP library.
Published 2011-10-18 · Modified
9.3EPSS 0.029
CVE-2012-4297
Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in Wireshark 1.6.x before 1.6.10 and 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a malformed packet.
Published 2012-08-16 · Modified
8.3EPSS 0.023
CVE-2010-2632
Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.
Published 2011-01-19 · Modified
7.81 PoCEPSS 0.350
CVE-2012-3210
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via unknown vectors related to Kernel.
Published 2012-10-17 · Modified
7.8EPSS 0.028
CVE-2014-6508
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to iSCSI Data Mover (IDM).
Published 2014-10-15 · Modified
7.8EPSS 0.028
CVE-2013-3753
Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via vectors related to Kernel/STREAMS framework.
Published 2013-07-17 · Modified
7.8EPSS 0.028
CVE-2013-3748
Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via vectors related to Driver/IDM (iSCSI Data Mover).
Published 2013-07-17 · Modified
7.8EPSS 0.028
CVE-2011-3543
Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to iSCSI DataMover (IDM).
Published 2011-10-18 · Modified
7.8EPSS 0.026
CVE-2012-3189
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability, related to COMSTAR.
Published 2012-10-17 · Modified
7.8EPSS 0.020
CVE-2010-4457
Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to SMB and CIFS.
Published 2011-01-19 · Modified
7.8EPSS 0.019
CVE-2012-0094
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability, related to TCP/IP.
Published 2012-01-18 · Modified
7.8EPSS 0.017
CVE-2011-2287
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to fingerd.
Published 2011-07-21 · Modified
7.8EPSS 0.014
CVE-2011-0841
Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to TCP/IP.
Published 2011-04-20 · Modified
7.8EPSS 0.013
CVE-2014-4276
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Common Internet File System (CIFS).
Published 2014-10-15 · Modified
7.5EPSS 0.024
CVE-2013-3750
Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/VM
Published 2013-07-17 · Modified
7.2EPSS 0.004
CVE-2014-4282
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel/X86.
Published 2014-10-15 · Modified
7.2EPSS 0.004
CVE-2012-3204
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management.
Published 2012-10-17 · Modified
7.2EPSS 0.004
CVE-2012-3199
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Gnome Trusted Extension.
Published 2012-10-17 · Modified
7.2EPSS 0.004
CVE-2014-6473
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Framework.
Published 2014-10-15 · Modified
7.2EPSS 0.004
CVE-2014-6510
Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility.
Published 2015-01-21 · Modified
7.2EPSS 0.003
CVE-2014-6529
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hermon HCA PCIe driver.
Published 2014-10-15 · Modified
6.8EPSS 0.011
CVE-2014-6470
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Archive Utility.
Published 2014-10-15 · Modified
6.8EPSS 0.003
CVE-2012-0100
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kerberos.
Published 2012-01-18 · Modified
6.8EPSS 0.003
CVE-2014-6518
Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS).
Published 2015-01-21 · Modified
6.6EPSS 0.003
CVE-2012-1691
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Privileges.
Published 2012-05-03 · Modified
6.6EPSS 0.003
CVE-2011-0800
Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Administration Utilities.
Published 2011-04-20 · Modified
6.5EPSS 0.003
CVE-2013-3757
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect integrity and availability via vectors related to SMF/File Locking Services.
Published 2013-07-17 · Modified
6.4EPSS 0.029
CVE-2013-0405
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality and integrity via vectors related to NFS client mounts and IPv6.
Published 2013-04-17 · Modified
6.4EPSS 0.020
CVE-2013-3786
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.
Published 2013-07-17 · Modified
6.0EPSS 0.003
CVE-2012-1683
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to gssd.
Published 2012-05-03 · Modified
5.9EPSS 0.003
CVE-2012-4294
Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.
Published 2012-08-16 · Modified
5.8EPSS 0.033
CVE-2012-3209
Unspecified vulnerability in Oracle Sun Solaris 10 and 11, when running on SPARC, allows local users to affect integrity and availability via unknown vectors related to Logical Domain (LDOM).
Published 2012-10-17 · Modified
5.6EPSS 0.004
CVE-2012-1687
Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability, related to Logical Domains (LDOM).
Published 2012-07-17 · Modified
5.6EPSS 0.004
CVE-2011-3515
Unspecified vulnerability in the Oracle Solaris 10 and 11 Express allows local users to affect integrity and availability via unknown vectors related to Process File System (procfs).
Published 2011-10-18 · Modified
5.6EPSS 0.004
CVE-2012-4298
Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to execute arbitrary code via a crafted packet-trace file that triggers a buffer overflow.
Published 2012-08-16 · Modified
5.4EPSS 0.060
CVE-2011-0820
Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Kernel.
Published 2011-04-20 · Modified
5.4EPSS 0.015
CVE-2015-0375
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect confidentiality via unknown vectors related to Network.
Published 2015-01-21 · Modified
5.0EPSS 0.026
CVE-2013-0398
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality via unknown vectors related to Utility/Remote Execution Server (in.rexecd).
Published 2013-07-17 · Modified
5.0EPSS 0.026
CVE-2012-4287
epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length.
Published 2012-08-16 · Modified
5.0EPSS 0.024
1 / 4Next →