| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319. |
| Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307. |
| pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871. |
| Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value. |
| Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX. |
| Buffer overflow of rlogin program using TERM environmental variable. |
| Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges. |
| Buffer overflow in xlock program allows local users to execute commands as root. |
| DNS cache poisoning via BIND, by predictable query IDs. |
| Local user gains root privileges via buffer overflow in rdist, via expstr() function. |
| Buffer overflow in statd allows root privileges. |
| Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. |
| Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). |
| nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers. |
| Solaris volrmmount program allows attackers to read any file. |
| Buffer overflow in NIS+, in Sun's rpc.nisd program. |
| Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind. |