Vulnerabilities > SUN > Medium

DATE CVE VULNERABILITY TITLE RISK
1996-12-18 CVE-1999-0128 Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
network
low complexity
sco sun digital ibm linux
5.0
1996-12-03 CVE-1999-0129 Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
local
low complexity
eric-allman sco sun hp ibm bsdi freebsd
4.6
1996-08-03 CVE-1999-1413 Unspecified vulnerability in SUN Solaris and Sunos
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g.
local
low complexity
sun
4.6
1996-04-24 CVE-1999-0019 Delete or create a file via rpc.statd, due to invalid information.
network
low complexity
data-general ncr sgi ibm nighthawk sco sun
5.0
1996-02-21 CVE-1999-0143 Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.
local
low complexity
process-software mit sun
4.6
1995-08-29 CVE-1999-0164 Unspecified vulnerability in SUN Sunos 5.3/5.4
A race condition in the Solaris ps command allows an attacker to overwrite critical files.
local
high complexity
sun
6.2
1994-05-13 CVE-1999-1388 Unspecified vulnerability in SUN Sunos 4.1
passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.
local
high complexity
sun
6.2
1991-12-06 CVE-1999-0167 Unspecified vulnerability in SUN Sunos 4.1.1
In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.
local
low complexity
sun
4.6
1991-10-22 CVE-1999-1468 rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.
local
high complexity
next sgi cray sun
6.2
1991-01-15 CVE-1999-1258 Unspecified vulnerability in SUN Sunos
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.
network
low complexity
sun
5.0