Skip to main content

Vendor/product archive

sun / sunos CVEs

Beta · best-effort

500 CVEs tagged to sun / sunos63 Critical, 137 High, 210 Medium, 90 Low, 0 Unrated.

CVE-2003-1080

Published Feb 11, 2003

Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0027

Published Feb 7, 2003

Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1075

Published Jan 27, 2003

Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1071

Published Jan 3, 2003

rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before execu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1763

Published Dec 31, 2002

The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1871

Published Dec 31, 2002

pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which al…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1980

Published Dec 31, 2002

Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2197

Published Dec 31, 2002

Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2203

Published Dec 31, 2002

Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2327

Published Dec 31, 2002

Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1584

Published Dec 27, 2002

Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain p…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1296

Published Dec 23, 2002

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t stru…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1587

Published Dec 4, 2002

The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the appl…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1586

Published Dec 3, 2002

Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a nul…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1585

Published Nov 8, 2002

Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1590

Published Oct 29, 2002

The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1228

Published Oct 28, 2002

Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1589

Published Oct 24, 2002

Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of serv…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-0884

Published Oct 4, 2002

Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execut…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0885

Published Oct 4, 2002

Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arb…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 500 CVEsPage 16 of 20