SunCVEs & Vulnerabilities

1,711 CVEs affecting Sun products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

1,711 CVEs→ All vendors

Most Affected Products

jre 6,495opensolaris 5,914sdk 4,078jdk 3,312sunos 1,461solaris 1,104java system identity manager 68j2se 55
CVE-1999-0185HIGH

In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.

1 Oct 1997
7.5
CVSS
CVE-1999-0295HIGH

Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.

1 Oct 1997
7.2
CVSS
CVE-1999-0300HIGH

nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.

1 Oct 1997
7.5
CVSS
CVE-1999-1225MEDIUM

rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.

24 Aug 1997
5.0
CVSS
CVE-1999-0024MEDIUM

DNS cache poisoning via BIND, by predictable query IDs.

13 Aug 1997
5.0
CVSS
CVE-1999-0301HIGHpoc

Buffer overflow in SunOS/Solaris ps command.

1 Aug 1997
7.2
CVSS
CVE-1999-1419HIGH

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

30 Jul 1997
7.2
CVSS
CVE-1999-0169CRITICAL

NFS allows attackers to read and write any file on the system by specifying a false UID.

1 Jul 1997
10.0
CVSS
CVE-1999-1423LOWpoc

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

26 Jun 1997
2.1
CVSS
CVE-1999-1192HIGH

Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

24 Jun 1997
7.2
CVSS
CVE-1999-0033HIGH

Command execution in Sun systems via buffer overflow in the at program.

12 Jun 1997
7.2
CVSS
CVE-1999-0189HIGH

Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.

4 Jun 1997
7.5
CVSS
CVE-1999-1449LOW

SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.

19 May 1997
2.1
CVSS
CVE-1999-1191HIGHpoc

Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

19 May 1997
7.2
CVSS
CVE-1999-1402LOWpoc

The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

17 May 1997
2.1
CVSS
CVE-1999-1158HIGHpoc

Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.

13 May 1997
7.2
CVSS
CVE-1999-0040HIGHpoc

Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

1 May 1997
7.2
CVSS
CVE-1999-0038HIGHpoc

Buffer overflow in xlock program allows local users to execute commands as root.

26 Apr 1997
8.4
CVSS
CVE-1999-0315HIGHpoc

Buffer overflow in Solaris fdformat command gives root access to local users.

1 Apr 1997
7.2
CVSS
CVE-1999-0165CRITICAL

NFS cache poisoning.

1 Mar 1997
10.0
CVSS
CVE-1999-0318HIGH

Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.

1 Mar 1997
7.2
CVSS
CVE-1999-0868HIGH

ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.

20 Feb 1997
7.2
CVSS
CVE-1999-0109HIGHpoc

Buffer overflow in ffbconfig in Solaris 2.5.1.

10 Feb 1997
7.2
CVSS
CVE-1999-0046CRITICALpoc

Buffer overflow of rlogin program using TERM environmental variable.

6 Feb 1997
10.0
CVSS
CVE-1999-0298HIGH

ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

5 Feb 1997
7.5
CVSS
CVE-1999-0369HIGHpoc

The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.

1 Feb 1997
7.2
CVSS
CVE-1999-0966HIGH

Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].

27 Jan 1997
7.2
CVSS
CVE-1999-0051HIGHpoc

Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.

6 Jan 1997
7.2
CVSS
CVE-1999-0166MEDIUM

NFS allows users to use a "cd .." command to access other directories besides the exported file system.

1 Jan 1997
5.0
CVSS
CVE-1999-0217MEDIUM

Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.

1 Jan 1997
5.0
CVSS
CVE-1999-0345MEDIUM

Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

1 Jan 1997
5.0
CVSS
CVE-1999-0517MEDIUM

An SNMP community name is the default (e.g. public), null, or missing.

1 Jan 1997
5.9
CVSS
CVE-1999-0626NONE

A version of rusers is running that exposes valid user information to any entity on the network.

1 Jan 1997
0.0
CVSS
CVE-1999-1026HIGHpoc

aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.

20 Dec 1996
7.2
CVSS
CVE-1999-0128MEDIUMpoc

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

18 Dec 1996
5.0
CVSS
CVE-1999-0129MEDIUM

Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

3 Dec 1996
4.6
CVSS
CVE-1999-0277HIGH

The WorkMan program can be used to overwrite any file to get root access.

28 Oct 1996
7.2
CVSS
CVE-1999-0032HIGHpoc

Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.

25 Oct 1996
7.2
CVSS
CVE-1999-0132LOW

Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.

15 Aug 1996
2.1
CVSS
CVE-1999-0134HIGH

vold in Solaris 2.x allows local users to gain root access.

6 Aug 1996
7.2
CVSS
CVE-1999-1413MEDIUMpoc

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

3 Aug 1996
4.6
CVSS
CVE-1999-0136HIGH

Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.

31 Jul 1996
7.2
CVSS
CVE-1999-0135HIGH

admintool in Solaris allows a local user to write to arbitrary files and gain root access.

25 Jul 1996
7.2
CVSS
CVE-1999-0023HIGHpoc

Local user gains root privileges via buffer overflow in rdist, via lookup() function.

24 Jul 1996
7.2
CVSS
CVE-1999-0022HIGH

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

3 Jul 1996
7.8
CVSS
CVE-1999-0019MEDIUM

Delete or create a file via rpc.statd, due to invalid information.

24 Apr 1996
5.0
CVSS
CVE-1999-0078LOW

pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

18 Apr 1996
1.9
CVSS
CVE-1999-0142HIGH

The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.

1 Mar 1996
7.5
CVSS
← PrevPage 35 / 36Next →