Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.0% | — | SUN OpensolarisSunosSUN Solaris | 11/3/2009 | 16/6/2026 | The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5… | |
| Modificada | Media (4.9) | 0.39% | — | SUN OpensolarisSunos | 6/3/2009 | 16/6/2026 | The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java WEB ConsoleSUN SolarisSunos | 12/12/2008 | 16/6/2026 | Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Sunos | 21/10/2008 | 16/6/2026 | The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. NOTE: this might be a duplicate of CVE-2007-0165. | |
| Modificada | Alta (7.1) | 1.7% | — | SUN OpensolarisSUN SolarisSunos | 13/8/2008 | 16/6/2026 | Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile… | |
| Modificada | Alta (9.3) | 5.7% | — | SUN OpensolarisSUN SolarisSunos | 8/8/2008 | 16/6/2026 | Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet. | |
| Modificada | Alta (9.3) | 14% | 💥 Exploit | SUN OpensolarisSUN SolarisSunos | 8/8/2008 | 16/6/2026 | Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet. | |
| Modificada | Alta (7.2) | 0.37% | — | Sunos | 4/8/2008 | 16/6/2026 | Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.33% | — | SUN OpensolarisSUN SolarisSunos | 31/7/2008 | 16/6/2026 | Unspecified vulnerability in the Solaris Platform Information and Control Library daemon (picld) in Sun Solaris 8 through 10, and OpenSolaris builds snv_01 through snv_95, allows local users to cause a denial of service via unknown vectors that prevent operation of utilities such as prtdiag, prtpicl, and prtfru. | |
| Modificada | Alta (7.8) | 2.5% | — | SUN SolarisSunos | 30/6/2008 | 16/6/2026 | The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets. | |
| Modificada | Alta (7.2) | 0.59% | — | SUN OpensolarisSUN SolarisSunos | 16/6/2008 | 16/6/2026 | Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the… | |
| Modificada | Media (4.9) | 0.34% | — | SUN OpensolarisSunos | 16/6/2008 | 16/6/2026 | Unspecified vulnerability in the Sun (1) UltraSPARC T2 and (2) UltraSPARC T2+ kernel modules in Sun Solaris 10, and OpenSolaris before snv_93, allows local users to cause a denial of service (panic) via unspecified vectors, probably related to core files. | |
| Modificada | Alta (10) | 16% | — | Sunos | 12/5/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.8) | 2.6% | — | Sunos | 9/5/2008 | 16/6/2026 | The TCP implementation in Sun Solaris 8, 9, and 10 allows remote attackers to cause a denial of service (CPU consumption and new connection timeouts) via a TCP SYN flood attack. | |
| Modificada | Media (6.6) | 0.34% | — | Sunos | 14/4/2008 | 16/6/2026 | Unspecified vulnerability in the floating point context switch implementation in Sun Solaris 9 and 10 on x86 platforms might allow local users to cause a denial of service (application exit), corrupt data, or trigger incorrect calculations via unknown vectors. | |
| Modificada | Media (4.3) | 6.2% | 💥 Exploit | SUN SolarisSunos | 24/3/2008 | 16/6/2026 | rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request. | |
| Modificada | Alta (10) | 2.6% | — | Sunos | 18/3/2008 | 16/6/2026 | A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root logins in a manner unintended by the vendor, which allows remote attackers to gain privileges via unspecified vectors. | |
| Modificada | Media (6.8) | 2.3% | — | SUN SolarisSunos | 29/2/2008 | 16/6/2026 | Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly. | |
| Modificada | Media (4.9) | 0.36% | — | Sunos | 15/1/2008 | 16/6/2026 | Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors. | |
| Modificada | Media (4.7) | 0.26% | — | SUN SolarisSunos | 4/12/2007 | 16/6/2026 | Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs. | |
| Modificada | Media (4.7) | 0.33% | — | Sunos | 10/11/2007 | 16/6/2026 | Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris 9 and 10 allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2004-1346. | |
| Modificada | Media (4.9) | 0.38% | — | Sunos | 12/10/2007 | 16/6/2026 | Unspecified vulnerability in "Solaris Auditing" in the Basic Security Module (BSM) in Sun Solaris 10, when configured for auditing of networking (nt) events, allows local users to cause a denial of service (panic) via unspecified vectors. | |
| Modificada | Media (4.9) | 0.97% | 💥 Exploit | Sunos | 5/10/2007 | 16/6/2026 | Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl. | |
| Modificada | Alta (7.6) | 2.2% | — | Sunos | 17/8/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in the Role Based Access Control (RBAC) functionality in Sun Solaris 8 allow remote attackers who know the password for a role to gain privileges via that role. | |
| Modificada | Media (4.3) | 1.1% | — | Sunos | 13/8/2007 | 16/6/2026 | The finger daemon (in.fingerd) in Sun Solaris 7 through 9 allows remote attackers to list all accounts that have certain nonstandard GECOS fields via a request composed of a single digit, as demonstrated by a "finger 9@host" command, a different vulnerability than CVE-2001-1503. |