Vulnerabilities > SUN > Solaris > 10

DATE CVE VULNERABILITY TITLE RISK
2008-05-23 CVE-2008-2418 Race Condition vulnerability in SUN Solaris 10
Race condition in the STREAMS Administrative Driver (sad) in Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.
local
sun CWE-362
4.7
2008-05-08 CVE-2008-2112 Privilege Escalation vulnerability in SUN RAY Server Software 4.0
Unspecified vulnerability in Sun Ray Kiosk Mode 4.0 allows local and remote authenticated Sun Ray administrators to gain root privileges via unknown vectors related to utconfig.
network
novell redhat sun
8.5
2008-05-06 CVE-2008-2090 Resource Management Errors vulnerability in SUN Solaris 10
Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.
network
low complexity
sun CWE-399
7.8
2008-05-06 CVE-2008-2089 Configuration vulnerability in SUN Solaris 10
Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.
network
low complexity
sun CWE-16
7.8
2008-04-14 CVE-2008-1780 Permissions, Privileges, and Access Controls vulnerability in SUN Solaris 10
Unspecified vulnerability in the labeled networking functionality in Solaris 10 Trusted Extensions allows applications in separate labeling zones to bypass labeling restrictions via unknown vectors.
local
low complexity
sun CWE-264
4.6
2008-04-14 CVE-2008-1779 Resource Management Errors vulnerability in SUN Solaris 10/8/9
Sun Solaris 8, 9, and 10 allows "remote privileged" users to cause a denial of service (panic) via unknown vectors related to self encapsulated IP packets.
network
low complexity
sun CWE-399
6.8
2008-04-06 CVE-2008-1684 Race Condition vulnerability in SUN Solaris 10
inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.
local
sun CWE-362
4.7
2008-03-24 CVE-2008-1480 Remote Denial of Service vulnerability in Sun Solaris 'rpc.metad'
rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.
network
sun
4.3
2008-03-17 CVE-2008-1356 Improper Authentication vulnerability in SUN Solaris 10
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.
local
sun CWE-287
6.3
2008-03-13 CVE-2008-1317 Local Denial of Service vulnerability in SUN Solaris 10
Unspecified vulnerability in the Inter-Process Communication (IPC) message queue subsystem in Sun Solaris 10 allows local users to cause a denial of service (reboot) via blocked I/O message queues.
local
low complexity
sun
4.9