| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack. |
| In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. |
| Buffer overflow in Sun's ping program can give root access to local users. |
| The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. |
| sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack. |
| NFS cache poisoning. |
| The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. |
| ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. |
| A race condition in the Solaris ps command allows an attacker to overwrite critical files. |
| Buffer overflows in Sun libnsl allow root access. |
| Delete or create a file via rpc.statd, due to invalid information. |
| Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. |
| Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. |
| Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname. |
| A Unix account has a default, null, blank, or missing password. |
| Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option. |
| Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter. |
| rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd. |
| Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option. |
| Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys. |