Skip to main content

Vendor/product archive

sun / solaris CVEs

Beta · best-effort

486 CVEs tagged to sun / solaris84 Critical, 143 High, 196 Medium, 63 Low, 0 Unrated.

CVE-2007-3471

Published Jun 28, 2007

Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3458

Published Jun 27, 2007

The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Name Service Caching Daemon (nscd) crash) via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3283

Published Jun 19, 2007

GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which mi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3248

Published Jun 18, 2007

Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3223

Published Jun 14, 2007

Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS reque…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3025

Published Jun 7, 2007

Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3093

Published Jun 6, 2007

Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3094

Published Jun 6, 2007

Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to exec…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3069

Published Jun 6, 2007

xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the ses…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2989

Published Jun 1, 2007

The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain pointer, which allows remote attackers to cause a denial of service (in.iked daemon…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2990

Published Jun 1, 2007

Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2882

Published May 30, 2007

Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of servi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2736

Published May 17, 2007

PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.

CVSS 10.0 · Critical

CVE-2007-1898

Published May 16, 2007

formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.

CVSS 5.8 · Medium

CVE-2007-2617

Published May 11, 2007

srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to re…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-2529

Published May 9, 2007

Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges vi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2465

Published May 2, 2007

Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to c…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1681

Published Apr 19, 2007

Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1794

Published Apr 2, 2007

The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 201-225 of 486 CVEsPage 9 of 20