Vulnerabilities
Vulnerable Software
Sun:  >> Solaris  >> 2.6  Security Vulnerabilities
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
CVSS Score
7.2
EPSS Score
0.004
Published
2002-07-23
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
CVSS Score
7.2
EPSS Score
0.003
Published
2002-07-03
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
CVSS Score
7.5
EPSS Score
0.474
Published
2002-07-03
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.
CVSS Score
10.0
EPSS Score
0.555
Published
2002-05-29
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.
CVSS Score
7.2
EPSS Score
0.002
Published
2002-04-02
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.
CVSS Score
7.2
EPSS Score
0.032
Published
2002-03-15
cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.
CVSS Score
5.0
EPSS Score
0.013
Published
2002-03-15
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.
CVSS Score
7.2
EPSS Score
0.001
Published
2002-03-15
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.
CVSS Score
7.2
EPSS Score
0.001
Published
2002-03-15
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.
CVSS Score
2.1
EPSS Score
0.002
Published
2001-12-31


Contact Us

Shodan ® - All rights reserved