Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Filtered by product Solaris
Total 545 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0687 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2024-02-28 7.5 HIGH N/A
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVE-2000-0118 2 Redhat, Sun 3 Linux, Solaris, Sunos 2024-02-28 7.2 HIGH N/A
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
CVE-2003-0028 10 Cray, Freebsd, Gnu and 7 more 13 Unicos, Freebsd, Glibc and 10 more 2024-02-28 7.5 HIGH N/A
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
CVE-1999-0213 1 Sun 2 Solaris, Sunos 2024-02-28 10.0 HIGH N/A
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
CVE-2004-1346 1 Sun 1 Solaris 2024-02-28 2.1 LOW N/A
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.
CVE-1999-1026 1 Sun 1 Solaris 2024-02-28 7.2 HIGH N/A
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
CVE-1999-0973 1 Sun 2 Solaris, Sunos 2024-02-28 10.0 HIGH N/A
Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.
CVE-2004-1359 1 Sun 2 Solaris, Sunos 2024-02-28 4.6 MEDIUM N/A
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.
CVE-1999-1137 1 Sun 2 Solaris, Sunos 2024-02-28 2.1 LOW N/A
The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.
CVE-2003-0669 1 Sun 2 Solaris, Sunos 2024-02-28 1.2 LOW N/A
Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.
CVE-1999-0190 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
CVE-1999-0099 5 Bsdi, Convex, Cray and 2 more 7 Bsd Os, Convexos, Spp-ux and 4 more 2024-02-28 10.0 HIGH N/A
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVE-1999-0848 2 Isc, Sun 3 Bind, Solaris, Sunos 2024-02-28 5.0 MEDIUM N/A
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
CVE-1999-0321 1 Sun 1 Solaris 2024-02-28 7.2 HIGH N/A
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
CVE-2000-0055 1 Sun 2 Solaris, Sunos 2024-02-28 7.2 HIGH N/A
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
CVE-1999-0057 5 Eric Allman, Freebsd, Hp and 2 more 7 Vacation, Freebsd, Hp-ux and 4 more 2024-02-28 7.5 HIGH N/A
Vacation program allows command execution by remote users through a sendmail command.
CVE-2002-0678 7 Caldera, Compaq, Hp and 4 more 9 Openunix, Unixware, Tru64 and 6 more 2024-02-28 7.2 HIGH N/A
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
CVE-2003-0201 6 Apple, Compaq, Hp and 3 more 8 Mac Os X, Tru64, Cifs-9000 Server and 5 more 2024-02-28 10.0 HIGH N/A
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
CVE-2003-1071 1 Sun 2 Solaris, Sunos 2024-02-28 2.1 LOW N/A
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
CVE-2004-1358 1 Sun 1 Solaris 2024-02-28 5.0 MEDIUM N/A
The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.