Vulnerabilities
Vulnerable Software
Sun:  >> Solaris  Security Vulnerabilities
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
CVSS Score
7.2
EPSS Score
0.003
Published
2005-06-29
Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-06-16
Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.
CVSS Score
4.6
EPSS Score
0.001
Published
2005-06-09
Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.
CVSS Score
5.0
EPSS Score
0.007
Published
2005-05-16
Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-05-11
The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
CVSS Score
7.5
EPSS Score
0.006
Published
2005-05-02
Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.
CVSS Score
5.0
EPSS Score
0.007
Published
2005-05-02
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
CVSS Score
3.6
EPSS Score
0.001
Published
2005-05-02
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
CVSS Score
7.2
EPSS Score
0.001
Published
2005-05-02
Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.
CVSS Score
4.6
EPSS Score
0.001
Published
2005-05-02


Contact Us

Shodan ® - All rights reserved