Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Filtered by product Sunos
Total 618 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0118 2 Redhat, Sun 3 Linux, Solaris, Sunos 2025-04-03 7.2 HIGH N/A
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
CVE-1999-0167 1 Sun 1 Sunos 2025-04-03 4.6 MEDIUM N/A
In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.
CVE-1999-0019 7 Data General, Ibm, Ncr and 4 more 10 Dg Ux, Aix, Mp-ras and 7 more 2025-04-03 5.0 MEDIUM N/A
Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0517 2 Hp, Sun 2 Hp-ux, Sunos 2025-04-03 7.5 HIGH N/A
An SNMP community name is the default (e.g. public), null, or missing.
CVE-1999-1507 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.
CVE-1999-0120 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.
CVE-1999-0188 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
The passwd command in Solaris can be subjected to a denial of service.
CVE-2001-0095 1 Sun 1 Sunos 2025-04-03 1.2 LOW N/A
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
CVE-2003-0058 2 Mit, Sun 4 Kerberos 5, Enterprise Authentication Mechanism, Solaris and 1 more 2025-04-03 5.0 MEDIUM N/A
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
CVE-1999-1021 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
CVE-2001-1244 7 Freebsd, Hp, Linux and 4 more 9 Freebsd, Hp-ux, Vvos and 6 more 2025-04-03 5.0 MEDIUM N/A
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
CVE-1999-0277 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
The WorkMan program can be used to overwrite any file to get root access.
CVE-2003-1067 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
CVE-2005-0488 3 Microsoft, Mit, Sun 3 Telnet Client, Kerberos 5, Sunos 2025-04-03 5.0 MEDIUM N/A
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
CVE-1999-0676 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVE-2003-1055 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.
CVE-2003-0028 10 Cray, Freebsd, Gnu and 7 more 13 Unicos, Freebsd, Glibc and 10 more 2025-04-03 7.5 HIGH N/A
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
CVE-2002-0033 1 Sun 2 Solaris, Sunos 2025-04-03 10.0 HIGH N/A
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.
CVE-2006-3664 1 Sun 2 Solaris, Sunos 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.
CVE-1999-1506 1 Sun 1 Sunos 2025-04-03 7.5 HIGH N/A
Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.