VendorsSunsunos5.5.1
Vulnerabilities

Sun Sunos 5.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

112CVEs
CVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
Published 2002-06-25 · Modified
10.08 PoCEPSS 0.947
CVE-2003-0201
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
Published 2003-04-15 · Modified
10.012 PoCEPSS 0.845
CVE-2002-0391
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
Published 2003-04-02 · Modified
10.0EPSS 0.581
CVE-1999-0046
Buffer overflow of rlogin program using TERM environmental variable.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.519
CVE-2003-0161
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
Published 2003-04-01 · Modified
10.02 PoCEPSS 0.388
CVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
Published 2002-03-09 · Modified
10.01 PoCEPSS 0.387
CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.290
CVE-1999-0003
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.246
CVE-2002-0679
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
Published 2003-04-02 · Modified
10.0EPSS 0.233
CVE-2003-0196
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
Published 2003-04-15 · Modified
10.0EPSS 0.228
CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Published 2001-01-22 · Modified
10.011 PoCEPSS 0.156
CVE-1999-0977
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
Published 2000-01-04 · Modified
10.05 PoCEPSS 0.126
CVE-1999-0696
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
Published 2000-06-02 · Modified
10.02 PoCEPSS 0.122
CVE-1999-0018
Buffer overflow in statd allows root privileges.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.105
CVE-1999-0210
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
Published 2000-06-02 · Modified
10.01 PoCEPSS 0.062
CVE-2002-1584
Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.
Published 2005-02-08 · Modified
10.0EPSS 0.057
CVE-1999-0011
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Published 1999-09-29 · Modified
10.0EPSS 0.055
CVE-1999-0097
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
Published 1999-09-29 · Modified
10.0EPSS 0.040
CVE-1999-0008
Buffer overflow in NIS+, in Sun's rpc.nisd program.
Published 1999-09-29 · Modified
10.0EPSS 0.039
CVE-1999-0973
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
Published 2000-01-04 · Modified
10.01 PoCEPSS 0.035
CVE-1999-0974
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
Published 2000-01-04 · Modified
10.0EPSS 0.032
CVE-1999-0213
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
Published 2000-02-04 · Modified
10.0EPSS 0.019
CVE-1999-0320
SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
Published 1999-09-29 · Modified
9.3EPSS 0.013
CVE-1999-0069
Solaris ufsrestore buffer overflow.
Published 1999-09-29 · Modified
8.42 PoCEPSS 0.014
CVE-1999-0038
Buffer overflow in xlock program allows local users to execute commands as root.
Published 1999-09-29 · Modified
8.42 PoCEPSS 0.013
CVE-1999-0502
A Unix account has a default, null, blank, or missing password.
Published 2000-02-04 · Modified
7.51 PoCEPSS 0.533
CVE-2002-1317
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
Published 2004-09-01 · Modified
7.51 PoCEPSS 0.240
CVE-2001-1328
Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.
Published 2004-09-01 · Modified
7.5EPSS 0.169
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published 2003-03-21 · Modified
7.5EPSS 0.150
CVE-1999-0185
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
Published 1999-09-29 · Modified
7.5EPSS 0.073
CVE-2002-0677
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Published 2002-07-12 · Modified
7.5EPSS 0.066
CVE-1999-0493
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.
Published 2000-06-02 · Modified
7.51 PoCEPSS 0.043
CVE-1999-0065
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
Published 1999-09-29 · Modified
7.5EPSS 0.032
CVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Published 2004-09-01 · Modified
7.5EPSS 0.027
CVE-1999-0687
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Published 2000-01-04 · Modified
7.5EPSS 0.022
CVE-1999-1432
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
Published 2002-03-09 · Modified
7.51 PoCEPSS 0.021
CVE-1999-0017
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Published 1999-09-29 · Modified
7.5EPSS 0.020
CVE-1999-0302
SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
Published 1999-09-29 · Modified
7.5EPSS 0.015
CVE-2001-1414
The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.
Published 2005-02-08 · Modified
7.5EPSS 0.015
CVE-1999-0189
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Published 2000-03-22 · Modified
7.5EPSS 0.012
1 / 3Next →