Skip to main content

Vendor/product archive

sun / solaris CVEs

Beta · best-effort

486 CVEs tagged to sun / solaris84 Critical, 143 High, 196 Medium, 63 Low, 0 Unrated.

CVE-2008-2418

Published May 23, 2008

Race condition in the STREAMS Administrative Driver (sad) in Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2089

Published May 6, 2008

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2090

Published May 6, 2008

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplifica…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1779

Published Apr 14, 2008

Sun Solaris 8, 9, and 10 allows "remote privileged" users to cause a denial of service (panic) via unknown vectors related to self encapsulated IP packets.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1780

Published Apr 14, 2008

Unspecified vulnerability in the labeled networking functionality in Solaris 10 Trusted Extensions allows applications in separate labeling zones to bypass labeling restrictions v…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1684

Published Apr 6, 2008

inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1480

Published Mar 24, 2008

rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1356

Published Mar 17, 2008

Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication v…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1317

Published Mar 13, 2008

Unspecified vulnerability in the Inter-Process Communication (IPC) message queue subsystem in Sun Solaris 10 allows local users to cause a denial of service (reboot) via blocked I…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1205

Published Mar 8, 2008

Unspecified vulnerability in the ipsecah kernel module in Sun Solaris 10, when a key management daemon for IPsec security associations is running, allows local users to cause a de…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1115

Published Mar 3, 2008

Unspecified vulnerability in Sun Solaris 8 directory functions allows local users to cause a denial of service (panic) via an unspecified sequence of system calls or commands.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1095

Published Feb 29, 2008

Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial o…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0933

Published Feb 25, 2008

Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vec…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0938

Published Feb 25, 2008

Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive k…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0836

Published Feb 20, 2008

Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectures allows local users to cause a denial of service (panic) via unspecified vect…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0730

Published Feb 12, 2008

The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a)…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0718

Published Feb 12, 2008

Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0242

Published Jan 12, 2008

Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6505

Published Dec 20, 2007

Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root,…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6413

Published Dec 17, 2007

Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup restrictions and obtain root a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 151-175 of 486 CVEsPage 7 of 20