Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Filtered by product Sunos
Total 609 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0065 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
CVE-1999-0840 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
CVE-1999-0190 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
CVE-2003-1071 1 Sun 2 Solaris, Sunos 2025-04-03 2.1 LOW N/A
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
CVE-2002-1199 3 Caldera, Sco, Sun 4 Openlinux, Openserver, Solaris and 1 more 2025-04-03 5.0 MEDIUM N/A
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
CVE-1999-1025 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
CVE-1999-1432 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
CVE-2000-0844 13 Caldera, Conectiva, Debian and 10 more 16 Openlinux, Openlinux Ebuilder, Openlinux Eserver and 13 more 2025-04-03 10.0 HIGH N/A
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
CVE-1999-1587 1 Sun 2 Solaris, Sunos 2025-04-03 2.1 LOW N/A
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.
CVE-2001-1555 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.
CVE-2006-3664 1 Sun 2 Solaris, Sunos 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.
CVE-1999-0046 10 Bsdi, Debian, Digital and 7 more 10 Bsd Os, Debian Linux, Ultrix and 7 more 2025-04-03 10.0 HIGH N/A
Buffer overflow of rlogin program using TERM environmental variable.
CVE-2003-1063 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.
CVE-1999-0848 2 Isc, Sun 3 Bind, Solaris, Sunos 2025-04-03 5.0 MEDIUM N/A
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
CVE-2001-0595 1 Sun 1 Sunos 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.
CVE-1999-0211 1 Sun 1 Sunos 2025-04-03 5.0 MEDIUM N/A
Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.
CVE-1999-0691 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2025-04-03 7.2 HIGH N/A
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
CVE-2002-1871 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
CVE-1999-0165 3 Bsdi, Linux, Sun 5 Bsd Os, Linux Kernel, Nfs and 2 more 2025-04-03 10.0 HIGH N/A
NFS cache poisoning.
CVE-2003-0058 2 Mit, Sun 4 Kerberos 5, Enterprise Authentication Mechanism, Solaris and 1 more 2025-04-03 5.0 MEDIUM N/A
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.