This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/o:sun:solaris:10 |
| Detail | |||
|---|---|---|---|
| Vendor | Sun | First view | 2008-01-15 |
| Product | Solaris | Last view | 2009-12-03 |
| Version | 10 | Type | Os |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/o:sun:solaris | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 7.2 | 2009-12-03 | CVE-2009-4191 | Local | Low | None Requ... | |
| 2.1 | 2009-11-29 | CVE-2009-4080 | Local | Low | None Requ... | |
| 6.8 | 2009-03-11 | CVE-2009-0873 | Network | Medium | None Requ... | |
| 4.9 | 2009-03-06 | CVE-2009-0838 | Local | Low | None Requ... | |
| 4.3 | 2008-12-12 | CVE-2008-5550 | Network | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 7.1 | 2008-08-13 | CVE-2008-3666 | Network | Medium | None Requ... | |
| 9.3 | 2008-08-08 | CVE-2008-0965 | Network | Medium | None Requ... | |
| 9.3 | 2008-08-08 | CVE-2008-0964 | Network | Medium | None Requ... | |
| 7.2 | 2008-08-04 | CVE-2008-3450 | Local | Low | None Requ... | |
| 2.1 | 2008-07-31 | CVE-2008-3426 | Local | Low | None Requ... | |
| 7.8 | 2008-06-30 | CVE-2008-2946 | Network | Low | None Requ... | |
| 4.9 | 2008-06-16 | CVE-2008-2708 | Local | Low | None Requ... | |
| 10 | 2008-05-12 | CVE-2008-2144 | Network | Low | None Requ... | |
| 7.8 | 2008-05-09 | CVE-2008-2121 | Network | Low | None Requ... | |
| 6.6 | 2008-04-14 | CVE-2008-1778 | Local | Low | None Requ... | |
| 4.3 | 2008-03-24 | CVE-2008-1480 | Network | Medium | None Requ... | |
| 10 | 2008-03-18 | CVE-2008-1369 | Network | Low | None Requ... | |
| 6.8 | 2008-02-29 | CVE-2008-1095 | Network | Low | Requires ... | |
| 4.9 | 2008-01-15 | CVE-2008-0269 | Local | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 40% (4) | CWE-264 | Permissions, Privileges, and Access Controls |
| 20% (2) | CWE-399 | Resource Management Errors |
| 20% (2) | CWE-16 | Configuration |
| 10% (1) | CWE-134 | Uncontrolled Format String |
| 10% (1) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CAPEC : Common Attack Pattern Enumeration & Classificatio
| id | Name |
|---|---|
| CAPEC-2 | Inducing Account Lockout |
| CAPEC-82 | Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi... |
| CAPEC-147 | XML Ping of Death |
| CAPEC-228 | Resource Depletion through DTD Injection in a SOAP Message |
Oval Markup Language : Definitions
| OvalID | Name |
|---|---|
| oval:org.mitre.oval:def:5400 | Security Vulnerability in Solaris 10 Related to the dotoprocs() Routine |
| oval:org.mitre.oval:def:5318 | Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic |
| oval:org.mitre.oval:def:5742 | Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic |
| oval:org.mitre.oval:def:5511 | Security Vulnerability May Allow Firewall Compromise or Creation of Denial of... |
| oval:org.mitre.oval:def:5698 | The Solaris rpc.metad(1M) Daemon is Vulnerable to a Denial of Service (DoS) A... |
| id | Name |
|---|---|
| oval:org.mitre.oval:def:4950 | A Security Vulnerability in Floating Point Context Switch Implementation May ... |
| oval:org.mitre.oval:def:5269 | Security Vulnerabilities in Solaris Print Service May Lead to Denial of Servi... |
| oval:org.mitre.oval:def:5609 | A Security Vulnerability in the namefs Kernel module may result in Arbitrary ... |
| oval:org.mitre.oval:def:5128 | A Security Vulnerability in Solaris 10 involving the sendfilev() system call ... |
| oval:org.mitre.oval:def:5641 | A Security Vulnerability With the Solaris Crypto Driver May Cause a System Panic |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 60668 | OpenSolaris Unspecified Local Privilege Escalation |
| 60514 | Solaris LDAP Client Configuration Cache Daemon (ldap_cachemgr(1M)) Multiple U... |
| 52560 | Solaris NFS Daemon sec=sys / sec=krb5 Security Mode Restriction Bypass |
| 52508 | Solaris Crypto Pseudo Device Driver Unspecified Local DoS |
| 50971 | Sun Java Web Console console/faces/jsp/login/BeginLogin.jsp redirect_url Para... |
| id | Description |
|---|---|
| 47422 | Solaris snoop(1M) SMB Traffic Monitoring Multiple Unspecified Remote Format S... |
| 47421 | Solaris snoop(1M) SMB Traffic Monitoring Multiple Unspecified Remote Overflows |
| 47420 | Solaris namefs Kernel Module Unspecified Local Privilege Escalation |
| 47375 | Solaris sendfilev() System Call System Panic Remote DoS |
| 47255 | Solaris picld(1M) Unspecified Local DoS |
| 46558 | Solaris SNMP-DMI Mapper Subagent Ddaemon (snmpXdmid(1M)) Malformed Packet Rem... |
| 46147 | Solaris UltraSPARC Kernel Module Unspecified Local DoS |
| 44972 | Solaris Print Service Unspecified Remote DoS (6599950) |
| 44971 | Solaris Print Service Unspecified Remote Code Execution (6599100) |
| 44970 | Solaris Print Service Unspecified Remote Code Execution (6599099) |
| 44936 | Solaris TCP Implementation SYN Flood Remote DoS |
| 44366 | Solaris Floating Point Context Switch Multiple Method Local DoS |
| 43547 | Solaris on SPARC Enterprise Multiple File Root Login Config Weakness Unspecif... |
| 43275 | Solaris rpc.metad Malformed Traffic Remote DoS |
| 42156 | Solaris ip(7P) Crafted Packets Remote DoS |
| 42155 | Solaris ip(7P) Crafted Packets Firewall Security Policy Bypass |
| 40242 | Solaris dotoprocs() Function Unspecified Local DoS |
Milw0rm Exploits
| id | Description |
|---|---|
| 2008-08-29 | Sun Solaris <= 10 snoop(1M) Utility Remote Exploit |
| 2008-03-14 | SunOS 5.10 Sun Cluster rpc.metad Denial of Service PoC |











