Vulnerabilities > SUN > Solaris > 10

DATE CVE VULNERABILITY TITLE RISK
2008-12-12 CVE-2008-5550 URI Redirection vulnerability in SUN Java web Console, Solaris and Sunos
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.
network
sun
4.3
2008-12-11 CVE-2008-5423 Information Exposure vulnerability in SUN RAY Server Software and RAY Windows Connector
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.
local
low complexity
sun novell redhat CWE-200
4.3
2008-12-11 CVE-2008-5422 Permissions, Privileges, and Access Controls vulnerability in SUN RAY Server Software
Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors.
network
low complexity
sun novell redhat CWE-264
7.5
2008-11-18 CVE-2008-5133 Permissions, Privileges, and Access Controls vulnerability in SUN Opensolaris and Solaris
ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queries sent by named.
network
sun CWE-264
5.8
2008-11-17 CVE-2008-5111 Local Denial Of Service vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the socket function in Sun Solaris 10 and OpenSolaris snv_57 through snv_91, when InfiniBand hardware is not installed, allows local users to cause a denial of service (panic) via unknown vectors, related to the socksdpv_close function.
local
sun
4.7
2008-11-10 CVE-2008-5010 Remote Code Execution vulnerability in SUN Opensolaris and Solaris
in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.
network
low complexity
sun
critical
10.0
2008-09-22 CVE-2008-4160 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.
local
sun CWE-399
4.7
2008-09-19 CVE-2008-4131 Permissions, Privileges, and Access Controls vulnerability in SUN Solaris 10/8/9
Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.
local
low complexity
sun CWE-264
7.2
2008-09-02 CVE-2008-3875 Permissions, Privileges, and Access Controls vulnerability in SUN Opensolaris and Solaris
The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.
local
low complexity
sun CWE-264
7.2
2008-08-27 CVE-2008-3839 Local Denial of Service vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the NFS module in the kernel in Sun Solaris 10 and OpenSolaris snv_59 through snv_87, when configured as an NFS server without the nodevices option, allows local users to cause a denial of service (panic) via unspecified vectors.
local
sun
4.7