Vulnerabilities > SUN > Opensolaris > snv.39

DATE CVE VULNERABILITY TITLE RISK
2009-04-09 CVE-2009-1276 Information Exposure vulnerability in SUN Opensolaris and Solaris
XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.
local
low complexity
gnome sun CWE-200
2.1
2009-04-01 CVE-2009-1207 Race Condition vulnerability in SUN Opensolaris and Solaris
Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.
local
sun CWE-362
4.4
2009-03-17 CVE-2009-0924 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.
local
sun CWE-399
4.7
2009-03-17 CVE-2009-0923 Remote Denial Of Service vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.
network
low complexity
sun
7.8
2009-03-16 CVE-2009-0913 Local Denial Of Service vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.
local
sun
4.7
2009-03-12 CVE-2009-0875 Race Condition vulnerability in SUN Opensolaris and Solaris
Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
local
sun CWE-362
6.9
2009-03-12 CVE-2009-0874 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the door_call function.
local
low complexity
sun CWE-399
4.9
2009-03-11 CVE-2009-0873 Permissions, Privileges, and Access Controls vulnerability in SUN Opensolaris, Solaris and Sunos
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."
network
sun CWE-264
6.8
2009-03-11 CVE-2009-0872 Permissions, Privileges, and Access Controls vulnerability in SUN Opensolaris and Solaris
The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.
network
sun CWE-264
6.8
2009-03-10 CVE-2009-0870 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.
local
sun CWE-399
4.7