Skip to main content

Vendor/product archive

sun / solaris CVEs

Beta · best-effort

486 CVEs tagged to sun / solaris84 Critical, 143 High, 196 Medium, 63 Low, 0 Unrated.

CVE-2006-7140

Published Mar 7, 2007

The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which al…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1093

Published Feb 26, 2007

Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical

CVE-2006-7028

Published Feb 23, 2007

Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a denial of service (console hang) via a flood of small TCP/IP packets. NOTE: t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0914

Published Feb 14, 2007

Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0895

Published Feb 13, 2007

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0668

Published Feb 2, 2007

The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of servic…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0634

Published Jan 31, 2007

Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0503

Published Jan 25, 2007

Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0470

Published Jan 24, 2007

Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0393

Published Jan 19, 2007

Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 an…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0165

Published Jan 10, 2007

Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6494

Published Dec 13, 2006

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6495

Published Dec 13, 2006

Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6275

Published Dec 4, 2006

Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5726

Published Nov 6, 2006

alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structur…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5396

Published Oct 18, 2006

The tcp_fuse_rcv_drain function in the Sun Solaris 10 kernel before 20061017, when TCP Fusion is enabled, allows local users to cause a denial of service (system crash) via a TCP…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4842

Published Oct 12, 2006

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from se…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5213

Published Oct 10, 2006

Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregat…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5214

Published Oct 10, 2006

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort
Showing 226-250 of 486 CVEsPage 10 of 20