Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  ORACLE : Solaris 11
  NVIDIA : NVIDIA Driver For Solaris 1.0
  ORACLE : Solaris 10
  ORACLE : Solaris 9
  SUN : Solaris 5.8
  SUN : Solaris 2.4
  SUN : Solaris 2.5
  SUN : Solaris 7
  SUN : Solaris 2.8
  SUN : Solaris 2.6
  SUN : Solaris 2.7
Name:ORACLE : Solaris 8

9!Oracle / Sun / Peoplesoft applications multiple security vulnerabilities
updated since 25.07.2011
document Quarterly critical patch update closes 78 different vulnerabilities in all major applications.
8!Oracle / Sun applications multiple security vulneraebilities
updated since 15.07.2010
document Quarterly update fixed 59 different vulnerabilities.
7!Sun Solaris sadmind multiple security vulnerabilities
document Integer overflow, buffer overflow.
 Solaris integer overflow
document Integer overflow in SYS_kaio syscall.
6!Sun Solaris Solstice AdminSuite daemon buffer overflow
document Buffer overflow in sadmind adm_build_path() function.
 Sun Solaris snoop format string vulnerability
document Format string vulnerability on SMB traffic parsing.
 Sun Solaris finger information leak
document Additional accounts unformation is leaked if finger is requested with single digit argument.
6!Sun Solaris fragmented IP packets DoS
   
10!Sun Solaris unauthorized access
updated since 11.02.2007
document User's pasword is not checked in telnet session if F flag is set. On older versions defining TTYPROMPT variable allows unauthorized access with bin group privileges. Vulnerability is used by internet worm.
 Sun Solaris tip privilege escalation
document Privilege escalation to 'uucp' user.
6!Sun Solaris rpcbind DoS
   
 UnixWare / Solaris X11R6 buffer overflow
updated since 08.09.2006
document Buffer overflow in XKEYBOARD extension.
6!Multiple Sun Solaris security vulnerabilities
document Privilege escalation with Role-Based Access Control, privilege escalation with 'format' if granted "File System Management" or similar role.
 Sun Solaris LDAP client information leak
document Command parameters, including password are available from tasks list.
 Sun Solaris ps information leak
document ps -e allows to see environment variables for any process.
 Sun Solaris GSFS file system privilege escalation
   
 Sun Solaris XSun / Xprt privilege escalation
   
 Sun Solaris UFS file system driver DoS
document It's possible to cause "soft hang" if UFS logging is enabled.
6!ICMP and TCP timestamp attacks to reset TCP connections
updated since 13.04.2005
document By using different ICMP packet types and TCP timestamps values it's possible to cause TCP connection resets or performance decrease.
6!Sun Solaris DHCP utilities and DHCP client privilege escalation
updated since 27.01.2005
   
 Sun Solaris printd print daemon unauthorized files access
document It's possible to remove arbitrary files with printd user's privileges.
 Sun Solaris libmle privilege escalation
   
6!Solaris unprivileged port hijacking
updated since 20.04.2005
document It possible to bind a process to a non-privileged network port, which already has been bound
6!Multiple hardware platforms hyper threading technology systems information leak
updated since 13.05.2005
document Unprivileged thread can read data from privileged thread memory from CPU cache memory.
 Multiple Sun Solaris perl modules problems
document Safe.pm protection bypass, CGI.pm crossite scripting.
 Sun Solaris lpadmin symbolic links problem
   
 Sun Solaris automountd DoS
document It's possible to stop automountd by accessing /xfn/_x500.
6!Solaris GSS API privilege escalation
document Ralative part is used to load library.
 Sun Solaris kcms_configure (Kodak Color Management System) symbolic links problem
document Symbolic links problem then accessing current directory KCS_ClogFile file with elevated privileges.
 Sun Solaris FTP server system wide DoS
document By issuing PASV command it's possible to consume all available TCP ports.
 Sun Solaris arp flood DoS
document ARP flood causes system to hang.
 Sun Solaris UDP endpoints DoS
document Heavy UDP usage with large number of open sockets can cause system to panic.
6!Solaris in.rwhod privilege escalation
   
6!Solaris ping buffer overflow
   
 Solaris LDAP_RBAC privilege escalation
   
6!Solaris in.named DoS
document DoS during dynamic update handling.
 Solaris dtmail format string bug
document format string bug in argv[0] allows privilege escalation to gid group.
7!dtlogin buffer overflow
updated since 24.03.2004
document Buffer overflow during XDMCP parsing.
7!Solaris vfs_getvfssw() call directory traversal
document Vulnerability allow local user to load kernel module.
6!Sun Solaris passwd priviledge escalation
   
6!Sun Solaris Xsun buffer overflow
updated since 03.04.2002
document Heap overflow in -co option.
7!Sun Solaris Runtime Linker buffer overflow
document Buffer overflow on LD_PRELOAD environment variable parsing.
6!Multiple SNMP problems
updated since 13.02.2002
document Multiple problems in different SNMP implementation can lead to DoS, remote code execution, etc.
6!Solaris syslogd buffer overflow
document Buffer overflow on files larger than 1024 bytes.
7!Sun Solaris dtsession buffer overflow
document Heap overflow on HOME environment variable parsing.
10!Buffer overflow in Sun rpc
updated since 31.07.2002
document Buffer overflow in xdr_array primitive
8!Sun Solaris at unauthorized file removing
document Directory traversal in at -r paramter.
6!Sun Solaris Kodak Color Management System directory traversal)
document Directory traversal in KCS_OPEN_PROFILE may be exploited via ToolTalk.
9!Solaris priocntl() privelege escalation
document During external module loaging path is not checked.
 Sun X Window Font Service buffer overflow
   
7!yellow pages unauthorized access
updated since 10.10.2002
document Vulnerabilities in ypserv and ypxfrd allows file system access with root privileges.
10!Buffer overfllow in /bin/login under System V
updated since 13.12.2001
document Buffer overflow on large name= request. Heap overflow in TTYPROMPT is trivially exploitable with remote root compromise.
7!Multiple bugs in CDE ToolTalk
updated since 11.07.2002
document Incomplete input validation in different remote calls.
8!Solaris LPD buffer overflow
   
9!Multiple bugs in Solaris utils
updated since 30.04.2002
document Local and remoter root compromise via buffer overflows and remote DoS attacks.
8!Format string bug in rwalld
document Formaqt string bug on syslog() call
7!Buffer overflow in CDE dtprintinfo
document Buffer overflow in HELP subsistem.
 DoS через GNU fileutils
   
9!Переполнение буфера в службе dtspcd в CDE (buffer overflow)
   
6!Переполнениея буфера в Solaris (yppasswd, mailtool buffer overflow)
updated since 29.05.2001
   
9!Ошибка форматной строки в ToolTalk rpc.ttdbserverd (format string)
   
8!Дырка в Solaris SNMP to DMI mapper daemon (buffer overflow)
updated since 15.03.2001
   
7!Переполнение буфера в xlock под Solaris (buffer overflow)
   
 Переполнение буфера в libsldap под Solaris (buffer overflow)
   
9!Переполнение буфера в lpd в Solaris (buffer overflow)
   
 Ошибка форматной строки в at из Solaris (NLS format string)
   
9!Дырка в Solaris на Intel (level evaluation)
   
 Дырка в mailx под Solaris (buffer overflow)
   
10!Очень серьезная ошибка во многих (BSD) ftpd (glob expansion)
   
 Дырка в tip под Solaris (buffer overflow)
   
7!Дырка в Solaris (pam_ldap authorization)
   
 Дырка в Solaris (ximp40)
   
6!NAPTHA - DoS через открытые/полуоткрытые соединения
updated since 05.12.2000
   
9!Серьезная уязвимость многих Unix через locale в glibc
updated since 05.09.2000
   
6!Дырка в Sun AnswerBook2
   
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server