Solaris
Products
14- 3 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
17| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0069 | Hig | 0.58 | 8.4 | 0.01 | Apr 29, 1998 | Solaris ufsrestore buffer overflow. | ||
| CVE-2001-0594 | 0.03 | — | 0.00 | Aug 2, 2001 | kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument. | |||
| CVE-2001-0059 | 0.03 | — | 0.00 | Feb 12, 2001 | patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2000-0407 | 0.03 | — | 0.00 | May 12, 2000 | Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option. | |||
| CVE-2000-0032 | 0.03 | — | 0.03 | Dec 22, 1999 | Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database. | |||
| CVE-1999-0860 | 0.03 | — | 0.00 | Dec 1, 1999 | Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack. | |||
| CVE-1999-0859 | 0.03 | — | 0.00 | Dec 1, 1999 | Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly. | |||
| CVE-1999-0818 | 0.03 | — | 0.01 | Nov 20, 1999 | Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. | |||
| CVE-1999-0767 | 0.03 | — | 0.01 | Sep 8, 1999 | Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable. | |||
| CVE-1999-0773 | 0.03 | — | 0.00 | May 11, 1999 | Buffer overflow in Solaris lpset program allows local users to gain root access. | |||
| CVE-1999-0806 | 0.03 | — | 0.01 | May 10, 1999 | Buffer overflow in Solaris dtprintinfo program. | |||
| CVE-1999-0321 | 0.03 | — | 0.00 | Dec 1, 1998 | Buffer overflow in Solaris kcms_configure command allows local users to gain root access. | |||
| CVE-2023-24040 | 0.00 | — | 0.00 | Jan 21, 2023 | dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection… | |||
| CVE-1999-0952 | 0.00 | — | 0.00 | Jan 28, 1999 | Buffer overflow in Solaris lpstat via class argument allows local users to gain root access. | |||
| CVE-1999-0568 | 0.00 | — | 0.01 | Jan 1, 1999 | rpc.admind in Solaris is not running in a secure mode. | |||
| CVE-1999-1025 | 0.00 | — | 0.00 | Nov 12, 1998 | CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string. | |||
| CVE-1999-1027 | 0.00 | — | 0.00 | May 7, 1998 | Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program. |
- risk 0.58cvss 8.4epss 0.01
Solaris ufsrestore buffer overflow.
- CVE-2001-0594Aug 2, 2001risk 0.03cvss —epss 0.00
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.
- CVE-2001-0059Feb 12, 2001risk 0.03cvss —epss 0.00
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2000-0407May 12, 2000risk 0.03cvss —epss 0.00
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
- CVE-2000-0032Dec 22, 1999risk 0.03cvss —epss 0.03
Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.
- CVE-1999-0860Dec 1, 1999risk 0.03cvss —epss 0.00
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
- CVE-1999-0859Dec 1, 1999risk 0.03cvss —epss 0.00
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
- CVE-1999-0818Nov 20, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
- CVE-1999-0767Sep 8, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
- CVE-1999-0773May 11, 1999risk 0.03cvss —epss 0.00
Buffer overflow in Solaris lpset program allows local users to gain root access.
- CVE-1999-0806May 10, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris dtprintinfo program.
- CVE-1999-0321Dec 1, 1998risk 0.03cvss —epss 0.00
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
- CVE-2023-24040Jan 21, 2023risk 0.00cvss —epss 0.00
dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection…
- CVE-1999-0952Jan 28, 1999risk 0.00cvss —epss 0.00
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
- CVE-1999-0568Jan 1, 1999risk 0.00cvss —epss 0.01
rpc.admind in Solaris is not running in a secure mode.
- CVE-1999-1025Nov 12, 1998risk 0.00cvss —epss 0.00
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
- CVE-1999-1027May 7, 1998risk 0.00cvss —epss 0.00
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.