SunCVEs & Vulnerabilities
1,711 CVEs affecting Sun products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
Most Affected Products
The passwd command in Solaris can be subjected to a denial of service.
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
Vacation program allows command execution by remote users through a sendmail command.
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
Buffer overflow in Sun's ping program can give root access to local users.
SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.
Solaris SUNWadmap can be exploited to obtain root access.
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.
NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.
Sun's ftpd daemon can be subjected to a denial of service.
Buffer overflow in NIS+, in Sun's rpc.nisd program.
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Buffer overflows in Sun libnsl allow root access.
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
Solaris ufsrestore buffer overflow.
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.
SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.
The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.
A Unix account has a default, null, blank, or missing password.
Solaris volrmmount program allows attackers to read any file.
Buffer overflow in SGI IRIX mailx program.
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Denial of service through Solaris 2.5.1 telnet by sending ^D characters.
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
Teardrop IP denial of service.
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Buffer overflow in statd allows root privileges.
Land IP denial of service.
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.
Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.
Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).