VYPR

Vendor CVEs

Sun Corporation

All CVEs

1,847 total · sorted by risk
  • CVE-1999-0722Aug 8, 1999
    risk 0.00cvss —epss 0.02

    The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.

  • CVE-1999-1023Jun 10, 1999
    risk 0.00cvss —epss 0.00

    useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.

  • CVE-1999-0440Mar 1, 1999
    risk 0.00cvss —epss 0.04

    The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.

  • CVE-1999-0223Mar 1, 1999
    risk 0.00cvss —epss 0.00

    Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.

  • CVE-1999-0408Feb 25, 1999
    risk 0.00cvss —epss 0.02

    Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

  • CVE-1999-0370Feb 10, 1999
    risk 0.00cvss —epss 0.00

    In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.

  • CVE-1999-0952Jan 28, 1999
    risk 0.00cvss —epss 0.00

    Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

  • CVE-1999-0568Jan 1, 1999
    risk 0.00cvss —epss 0.02

    rpc.admind in Solaris is not running in a secure mode.

  • CVE-1999-0188Dec 17, 1998
    risk 0.00cvss —epss 0.00

    The passwd command in Solaris can be subjected to a denial of service.

  • CVE-1999-0139Dec 12, 1998
    risk 0.00cvss —epss 0.00

    Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.

  • CVE-1999-1025Nov 12, 1998
    risk 0.00cvss —epss 0.00

    CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.

  • CVE-1999-0254Nov 2, 1998
    risk 0.00cvss —epss 0.04

    A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.

  • CVE-1999-0186Oct 1, 1998
    risk 0.00cvss —epss 0.04

    In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.

  • CVE-1999-0056Sep 9, 1998
    risk 0.00cvss —epss 0.00

    Buffer overflow in Sun's ping program can give root access to local users.

  • CVE-1999-0302Sep 1, 1998
    risk 0.00cvss —epss 0.02

    SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.

  • CVE-1999-0065Aug 31, 1998
    risk 0.00cvss —epss 0.03

    Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.

  • CVE-1999-0339Aug 1, 1998
    risk 0.00cvss —epss 0.00

    Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.

  • CVE-1999-0263Jul 16, 1998
    risk 0.00cvss —epss 0.00

    Solaris SUNWadmap can be exploited to obtain root access.

  • CVE-1999-1297Jul 15, 1998
    risk 0.00cvss —epss 0.00

    cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.

  • CVE-1999-0213Jul 15, 1998
    risk 0.00cvss —epss 0.02

    libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.

  • CVE-1999-0797Jun 29, 1998
    risk 0.00cvss —epss 0.01

    NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.

  • CVE-1999-0054Jun 10, 1998
    risk 0.00cvss —epss 0.01

    Sun's ftpd daemon can be subjected to a denial of service.

  • CVE-1999-0008Jun 8, 1998
    risk 0.00cvss —epss 0.04

    Buffer overflow in NIS+, in Sun's rpc.nisd program.

  • CVE-1999-0303May 21, 1998
    risk 0.00cvss —epss 0.00

    Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.

  • CVE-1999-0055May 14, 1998
    risk 0.00cvss —epss 0.00

    Buffer overflows in Sun libnsl allow root access.

  • CVE-1999-1027May 7, 1998
    risk 0.00cvss —epss 0.00

    Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.

  • CVE-1999-0212Apr 29, 1998
    risk 0.00cvss —epss 0.02

    Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.

  • CVE-1999-0010Apr 8, 1998
    risk 0.00cvss —epss 0.02

    Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

  • CVE-1999-0190Apr 8, 1998
    risk 0.00cvss —epss 0.00

    Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.

  • CVE-1999-1118Mar 11, 1998
    risk 0.00cvss —epss 0.00

    ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.

  • CVE-1999-0320Mar 1, 1998
    risk 0.00cvss —epss 0.01

    SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.

  • CVE-1999-0795Mar 1, 1998
    risk 0.00cvss —epss 0.02

    The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.

  • CVE-1999-0296Feb 1, 1998
    risk 0.00cvss —epss 0.00

    Solaris volrmmount program allows attackers to read any file.

  • CVE-1999-0273Jan 1, 1998
    risk 0.00cvss —epss 0.01

    Denial of service through Solaris 2.5.1 telnet by sending ^D characters.

  • CVE-1999-0017Dec 10, 1997
    risk 0.00cvss —epss 0.02

    FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

  • CVE-1999-1426Nov 10, 1997
    risk 0.00cvss —epss 0.00

    Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.

  • CVE-1999-1428Nov 10, 1997
    risk 0.00cvss —epss 0.00

    Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.

  • CVE-1999-1427Nov 10, 1997
    risk 0.00cvss —epss 0.00

    Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.

  • CVE-1999-1424Nov 10, 1997
    risk 0.00cvss —epss 0.00

    Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

  • CVE-1999-1425Nov 10, 1997
    risk 0.00cvss —epss 0.00

    Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.

  • CVE-1999-0097Oct 29, 1997
    risk 0.00cvss —epss 0.04

    The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

  • CVE-1999-0300Oct 1, 1997
    risk 0.00cvss —epss 0.01

    nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.

  • CVE-1999-0295Oct 1, 1997
    risk 0.00cvss —epss 0.00

    Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.

  • CVE-1999-1225Aug 24, 1997
    risk 0.00cvss —epss 0.02

    rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.

  • CVE-1999-0024Aug 13, 1997
    risk 0.00cvss —epss 0.05

    DNS cache poisoning via BIND, by predictable query IDs.

  • CVE-1999-1419Jul 30, 1997
    risk 0.00cvss —epss 0.00

    Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

  • CVE-1999-0169Jul 1, 1997
    risk 0.00cvss —epss 0.02

    NFS allows attackers to read and write any file on the system by specifying a false UID.

  • CVE-1999-1192Jun 24, 1997
    risk 0.00cvss —epss 0.00

    Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

  • CVE-1999-0033Jun 12, 1997
    risk 0.00cvss —epss 0.01

    Command execution in Sun systems via buffer overflow in the at program.

  • CVE-1999-0189Jun 4, 1997
    risk 0.00cvss —epss 0.01

    Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.

Page 36 of 37