Vulnerabilities
Vulnerable Software
Sun:  >> Solaris  Security Vulnerabilities
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
CVSS Score
7.5
EPSS Score
0.006
Published
2003-02-28
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
CVSS Score
5.0
EPSS Score
0.193
Published
2003-02-19
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.
CVSS Score
5.0
EPSS Score
0.011
Published
2003-02-18
Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.
CVSS Score
1.2
EPSS Score
0.001
Published
2003-02-11
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.
CVSS Score
5.0
EPSS Score
0.652
Published
2003-02-07
Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.
CVSS Score
5.0
EPSS Score
0.009
Published
2003-01-27
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.
CVSS Score
2.1
EPSS Score
0.003
Published
2003-01-03
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.
CVSS Score
7.2
EPSS Score
0.001
Published
2002-12-31
Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.
CVSS Score
7.2
EPSS Score
0.001
Published
2002-12-31
Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.
CVSS Score
4.6
EPSS Score
0.001
Published
2002-12-31


Contact Us

Shodan ® - All rights reserved