Sun

Solaris

451 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.91%
  • Published 27.01.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.

Exploit
  • EPSS 0.32%
  • Published 03.01.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.

  • EPSS 0.06%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.

  • EPSS 0.06%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.

  • EPSS 0.1%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.

  • EPSS 0.05%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference.

  • EPSS 0.07%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.

  • EPSS 5.26%
  • Published 27.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.

  • EPSS 0.03%
  • Published 23.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

  • EPSS 2.13%
  • Published 23.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.