VYPR

sadmind

by Sun Corporation

CVEs (2)

  • CVE-2003-0722Sep 22, 2003
    risk 0.10cvss epss 0.89

    The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.

  • CVE-2008-3869May 26, 2009
    risk 0.01cvss epss 0.08

    Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters.