| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Denial of service by sending forged ICMP unreachable packets. |
| Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. |
| The SunView (SunTools) selection_svc facility allows remote users to read files. |
| Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. |
| The passwd command in Solaris can be subjected to a denial of service. |
| The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions. |
| In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. |
| NFS cache poisoning. |
| Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys. |
| The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |
| Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access. |
| Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. |
| Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. |
| Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root. |
| Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors. |
| The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities. |
| Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user. |
| Buffer overflow in ffbconfig in Solaris 2.5.1. |
| The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character). |
| Buffer overflow of rlogin program using TERM environmental variable. |