Vendor CVEs
Solaris
All CVEs
22 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0069 | Hig | 0.58 | 8.4 | 0.01 | Apr 29, 1998 | Solaris ufsrestore buffer overflow. | ||
| CVE-2023-24040 | Hig | 0.46 | 7.1 | 0.00 | Jan 21, 2023 | dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection… | ||
| CVE-2008-5689 | 0.03 | — | 0.01 | Dec 19, 2008 | tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference. | |||
| CVE-2001-0594 | 0.03 | — | 0.01 | Aug 2, 2001 | kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument. | |||
| CVE-2001-0401 | 0.03 | — | 0.01 | Jun 18, 2001 | Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable. | |||
| CVE-2000-0407 | 0.03 | — | 0.01 | May 12, 2000 | Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option. | |||
| CVE-1999-0859 | 0.03 | — | 0.01 | Dec 1, 1999 | Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly. | |||
| CVE-1999-0818 | 0.03 | — | 0.01 | Nov 20, 1999 | Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. | |||
| CVE-1999-0908 | 0.03 | — | 0.02 | Sep 23, 1999 | Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter. | |||
| CVE-1999-0767 | 0.03 | — | 0.01 | Sep 8, 1999 | Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable. | |||
| CVE-1999-0773 | 0.03 | — | 0.01 | May 11, 1999 | Buffer overflow in Solaris lpset program allows local users to gain root access. | |||
| CVE-1999-0806 | 0.03 | — | 0.01 | May 10, 1999 | Buffer overflow in Solaris dtprintinfo program. | |||
| CVE-1999-0321 | 0.03 | — | 0.01 | Dec 1, 1998 | Buffer overflow in Solaris kcms_configure command allows local users to gain root access. | |||
| CVE-2008-7300 | 0.00 | — | 0.01 | Oct 5, 2011 | The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to… | |||
| CVE-2009-0923 | 0.00 | — | 0.02 | Mar 17, 2009 | Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key… | |||
| CVE-2009-0913 | 0.00 | — | 0.00 | Mar 16, 2009 | Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options. | |||
| CVE-2009-0361 | 0.00 | — | 0.00 | Feb 13, 2009 | Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME… | |||
| CVE-2009-0277 | 0.00 | — | 0.01 | Jan 27, 2009 | Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors. | |||
| CVE-2002-0088 | 0.00 | — | 0.00 | Mar 15, 2002 | Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path. | |||
| CVE-1999-1025 | 0.00 | — | 0.00 | Nov 12, 1998 | CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string. | |||
| CVE-1999-0213 | 0.00 | — | 0.02 | Jul 15, 1998 | libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind. | |||
| CVE-1999-1027 | 0.00 | — | 0.00 | May 7, 1998 | Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program. |
- risk 0.58cvss 8.4epss 0.01
Solaris ufsrestore buffer overflow.
- risk 0.46cvss 7.1epss 0.00
dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection…
- CVE-2008-5689Dec 19, 2008risk 0.03cvss —epss 0.01
tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.
- CVE-2001-0594Aug 2, 2001risk 0.03cvss —epss 0.01
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.
- CVE-2001-0401Jun 18, 2001risk 0.03cvss —epss 0.01
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
- CVE-2000-0407May 12, 2000risk 0.03cvss —epss 0.01
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
- CVE-1999-0859Dec 1, 1999risk 0.03cvss —epss 0.01
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
- CVE-1999-0818Nov 20, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
- CVE-1999-0908Sep 23, 1999risk 0.03cvss —epss 0.02
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
- CVE-1999-0767Sep 8, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
- CVE-1999-0773May 11, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris lpset program allows local users to gain root access.
- CVE-1999-0806May 10, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris dtprintinfo program.
- CVE-1999-0321Dec 1, 1998risk 0.03cvss —epss 0.01
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
- CVE-2008-7300Oct 5, 2011risk 0.00cvss —epss 0.01
The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to…
- CVE-2009-0923Mar 17, 2009risk 0.00cvss —epss 0.02
Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key…
- CVE-2009-0913Mar 16, 2009risk 0.00cvss —epss 0.00
Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.
- CVE-2009-0361Feb 13, 2009risk 0.00cvss —epss 0.00
Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME…
- CVE-2009-0277Jan 27, 2009risk 0.00cvss —epss 0.01
Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors.
- CVE-2002-0088Mar 15, 2002risk 0.00cvss —epss 0.00
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
- CVE-1999-1025Nov 12, 1998risk 0.00cvss —epss 0.00
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
- CVE-1999-0213Jul 15, 1998risk 0.00cvss —epss 0.02
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
- CVE-1999-1027May 7, 1998risk 0.00cvss —epss 0.00
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.