CVE-2009-0873
- EPSS 1.05%
- Veröffentlicht 11.03.2009 14:19:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files,...
CVE-2009-0838
- EPSS 0.06%
- Veröffentlicht 06.03.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.
CVE-2008-5550
- EPSS 0.5%
- Veröffentlicht 12.12.2008 18:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parame...
- EPSS 8.93%
- Veröffentlicht 21.10.2008 00:10:54
- Zuletzt bearbeitet 09.04.2025 00:30:58
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. NOTE: this mig...
CVE-2008-3666
- EPSS 0.78%
- Veröffentlicht 13.08.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrat...
CVE-2008-0964
- EPSS 28.55%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.
CVE-2008-0965
- EPSS 16.33%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.
CVE-2008-3450
- EPSS 0.06%
- Veröffentlicht 04.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.
CVE-2008-3426
- EPSS 0.07%
- Veröffentlicht 31.07.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the Solaris Platform Information and Control Library daemon (picld) in Sun Solaris 8 through 10, and OpenSolaris builds snv_01 through snv_95, allows local users to cause a denial of service via unknown vectors that preve...
CVE-2008-2946
- EPSS 0.72%
- Veröffentlicht 30.06.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.