SunCVEs & Vulnerabilities
1,711 CVEs affecting Sun products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
Most Affected Products
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.
rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.
DNS cache poisoning via BIND, by predictable query IDs.
Buffer overflow in SunOS/Solaris ps command.
Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.
NFS allows attackers to read and write any file on the system by specifying a false UID.
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
Command execution in Sun systems via buffer overflow in the at program.
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Buffer overflow in xlock program allows local users to execute commands as root.
Buffer overflow in Solaris fdformat command gives root access to local users.
NFS cache poisoning.
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
Buffer overflow in ffbconfig in Solaris 2.5.1.
Buffer overflow of rlogin program using TERM environmental variable.
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
NFS allows users to use a "cd .." command to access other directories besides the exported file system.
Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
An SNMP community name is the default (e.g. public), null, or missing.
A version of rusers is running that exposes valid user information to any entity on the network.
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
The WorkMan program can be used to overwrite any file to get root access.
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
vold in Solaris 2.x allows local users to gain root access.
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
Delete or create a file via rpc.statd, due to invalid information.
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.