Computer Security
[EN] securityvulns.ru
no-pyccku



See also
  ORACLE : Solaris 11
  NVIDIA : NVIDIA Driver For Solaris 1.0
  ORACLE : Solaris 10
  ORACLE : Solaris 9
  SUN : Solaris 5.8
  SUN : Solaris 2.4
  SUN : Solaris 2.5
  ORACLE : Solaris 8
  SUN : Solaris 2.8
  SUN : Solaris 2.6
  SUN : Solaris 2.7
Name:SUN : Solaris 7

 Sun Solaris finger information leak
document Additional accounts unformation is leaked if finger is requested with single digit argument.
10!Sun Solaris unauthorized access
updated since 11.02.2007
document User's pasword is not checked in telnet session if F flag is set. On older versions defining TTYPROMPT variable allows unauthorized access with bin group privileges. Vulnerability is used by internet worm.
 Sun Solaris XSun / Xprt privilege escalation
   
6!ICMP and TCP timestamp attacks to reset TCP connections
updated since 13.04.2005
document By using different ICMP packet types and TCP timestamps values it's possible to cause TCP connection resets or performance decrease.
 Sun Solaris printd print daemon unauthorized files access
document It's possible to remove arbitrary files with printd user's privileges.
 Sun Solaris libmle privilege escalation
   
6!Multiple hardware platforms hyper threading technology systems information leak
updated since 13.05.2005
document Unprivileged thread can read data from privileged thread memory from CPU cache memory.
 Sun Solaris lpadmin symbolic links problem
   
 Sun Solaris automountd DoS
document It's possible to stop automountd by accessing /xfn/_x500.
6!Solaris GSS API privilege escalation
document Ralative part is used to load library.
 Sun Solaris FTP server system wide DoS
document By issuing PASV command it's possible to consume all available TCP ports.
 Sun Solaris arp flood DoS
document ARP flood causes system to hang.
6!Solaris in.rwhod privilege escalation
   
6!Solaris ping buffer overflow
   
6!Sun Solaris Xsun buffer overflow
updated since 03.04.2002
document Heap overflow in -co option.
6!Multiple SNMP problems
updated since 13.02.2002
document Multiple problems in different SNMP implementation can lead to DoS, remote code execution, etc.
7!Sun Solaris lpq buffer overflow
document Stack overflow.
7!Sun Solaris dtsession buffer overflow
document Heap overflow on HOME environment variable parsing.
10!Buffer overflow in Sun rpc
updated since 31.07.2002
document Buffer overflow in xdr_array primitive
8!Sun Solaris at unauthorized file removing
document Directory traversal in at -r paramter.
6!Sun Solaris Kodak Color Management System directory traversal)
document Directory traversal in KCS_OPEN_PROFILE may be exploited via ToolTalk.
 FTP clients directory traversal
document Server can put relative or absolute path in filename.
 Sun X Window Font Service buffer overflow
   
7!yellow pages unauthorized access
updated since 10.10.2002
document Vulnerabilities in ypserv and ypxfrd allows file system access with root privileges.
7!Multiple bugs in CDE ToolTalk
updated since 11.07.2002
document Incomplete input validation in different remote calls.
8!Solaris LPD buffer overflow
   
9!Multiple bugs in Solaris utils
updated since 30.04.2002
document Local and remoter root compromise via buffer overflows and remote DoS attacks.
8!Format string bug in rwalld
document Formaqt string bug on syslog() call
7!Buffer overflow in CDE dtprintinfo
document Buffer overflow in HELP subsistem.
9!Переполнение буфера в службе dtspcd в CDE (buffer overflow)
   
7!Переполнение буфера в CDE dt-утилитах - libdtsvc (buffer overflow)
updated since 24.07.2001
   
9!Ошибка форматной строки в ToolTalk rpc.ttdbserverd (format string)
   
8!Дырка в Solaris SNMP to DMI mapper daemon (buffer overflow)
updated since 15.03.2001
   
7!Переполнение буфера в xlock под Solaris (buffer overflow)
   
9!Переполнение буфера в lpd в Solaris (buffer overflow)
   
 Ошибка форматной строки в at из Solaris (NLS format string)
   
9!Дырка в Solaris на Intel (level evaluation)
   
 Дырка в mailx под Solaris (buffer overflow)
   
 Дырки в различных утилитах под Solaris (buffer overflow)
updated since 10.04.2001
   
 Дырка в tip под Solaris (buffer overflow)
   
 Дырка в Solaris (ximp40)
   
 Дырка в write в Solaris
   
 Дырка в arp в Solaris
   
6!NAPTHA - DoS через открытые/полуоткрытые соединения
updated since 05.12.2000
   
9!Серьезная уязвимость многих Unix через locale в glibc
updated since 05.09.2000
   
                    

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru