Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Filtered by product Solaris
Total 545 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0369 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
CVE-2003-1563 1 Sun 3 Cluster, Solaris, Sunos 2024-02-28 4.0 MEDIUM N/A
Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.
CVE-2000-0844 13 Caldera, Conectiva, Debian and 10 more 16 Openlinux, Openlinux Ebuilder, Openlinux Eserver and 13 more 2024-02-28 10.0 HIGH N/A
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
CVE-2004-1360 1 Sun 2 Solaris, Sunos 2024-02-28 2.1 LOW N/A
Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.
CVE-1999-0125 3 Redhat, Sgi, Sun 4 Linux, Irix, Solaris and 1 more 2024-02-28 4.6 MEDIUM N/A
Buffer overflow in SGI IRIX mailx program.
CVE-1999-0054 1 Sun 2 Solaris, Sunos 2024-02-28 5.0 MEDIUM N/A
Sun's ftpd daemon can be subjected to a denial of service.
CVE-1999-0860 1 Sun 2 Solaris, Sunos 2024-02-28 2.1 LOW N/A
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
CVE-1999-1027 1 Sun 1 Solaris 2024-02-28 7.2 HIGH N/A
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
CVE-2000-0317 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
CVE-2001-0565 1 Sun 2 Solaris, Sunos 2024-02-28 4.6 MEDIUM N/A
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.
CVE-1999-0773 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
Buffer overflow in Solaris lpset program allows local users to gain root access.
CVE-2001-0594 1 Sun 2 Solaris, Sunos 2024-02-28 4.6 MEDIUM N/A
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.
CVE-2003-1061 1 Sun 2 Solaris, Sunos 2024-02-28 1.2 LOW N/A
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.
CVE-2002-0033 1 Sun 2 Solaris, Sunos 2024-02-28 10.0 HIGH N/A
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.
CVE-1999-0210 1 Sun 2 Solaris, Sunos 2024-02-28 10.0 HIGH N/A
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
CVE-2004-1351 1 Sun 2 Solaris, Sunos 2024-02-28 10.0 HIGH N/A
Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.
CVE-2004-1348 1 Sun 2 Solaris, Sunos 2024-02-28 5.0 MEDIUM N/A
Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).
CVE-1999-0018 3 Ibm, Sgi, Sun 4 Aix, Irix, Solaris and 1 more 2024-02-28 10.0 HIGH N/A
Buffer overflow in statd allows root privileges.
CVE-1999-0320 1 Sun 2 Solaris, Sunos 2024-02-28 9.3 HIGH N/A
SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
CVE-2004-1394 1 Sun 2 Solaris, Sunos 2024-02-28 4.6 MEDIUM N/A
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.