Vulnerabilities > SUN > Solaris > 10

DATE CVE VULNERABILITY TITLE RISK
2008-03-11 CVE-2008-1286 Unspecified vulnerability in SUN Java web Console 3.0.2/3.0.3/3.0.4
Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.
network
low complexity
sun linux
7.8
2008-03-08 CVE-2008-1205 Local Denial of Service vulnerability in SUN Solaris 10
Unspecified vulnerability in the ipsecah kernel module in Sun Solaris 10, when a key management daemon for IPsec security associations is running, allows local users to cause a denial of service (panic) via unspecified vectors.
local
low complexity
sun
4.9
2008-02-29 CVE-2008-1095 Permissions, Privileges, and Access Controls vulnerability in SUN Solaris and Sunos
Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.
network
low complexity
sun CWE-264
6.8
2008-02-25 CVE-2008-0938 Information Exposure vulnerability in SUN Solaris 10
Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.
local
sun CWE-200
4.7
2008-02-20 CVE-2008-0836 Denial-Of-Service vulnerability in SUN Solaris 10/9
Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectures allows local users to cause a denial of service (panic) via unspecified vectors that trigger a NULL pointer dereference in the vuid3ps2 module, a different issue than CVE-2007-5319.
local
low complexity
sun
4.9
2008-02-12 CVE-2008-0730 Permissions, Privileges, and Access Controls vulnerability in SUN Solaris 10
The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.
local
low complexity
sun CWE-264
4.6
2008-02-12 CVE-2008-0718 Improper Input Validation vulnerability in SUN Solaris 10/9
Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.
local
sun CWE-20
4.7
2007-12-20 CVE-2007-6482 Multiple vulnerability in Sun Ray Device Manager Daemon
Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
network
low complexity
sun linux
7.8
2007-12-17 CVE-2007-6413 Permissions, Privileges, and Access Controls vulnerability in SUN Solaris 10
Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup restrictions and obtain root access to a filesystem via NFS requests from a client root user.
network
sun CWE-264
critical
9.3
2007-12-04 CVE-2007-6225 Local Denial of Service vulnerability in SUN Solaris 10
Unspecified vulnerability in Sun Solaris 10, when 64bit mode is used on the x86 platform, allows local users in a Linux (lx) branded zone to cause a denial of service (panic) via unspecified vectors.
local
low complexity
sun
4.9