| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges. |
| Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user. |
| Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption." |
| Denial of service through Solaris 2.5.1 telnet by sending ^D characters. |
| Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. |
| Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. |
| vold in Solaris 2.x allows local users to gain root access. |
| Solaris volrmmount program allows attackers to read any file. |
| SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server. |
| The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |
| In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. |
| SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files. |
| The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions. |
| In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution. |
| Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. |
| Denial of service by sending forged ICMP unreachable packets. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. |
| Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. |
| nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers. |