Show filters
169 Total Results
Displaying 91-100 of 169
Sort by:
Attacker Value
Unknown
CVE-2005-0248
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
0
Attacker Value
Unknown
CVE-2005-0426
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.
0
Attacker Value
Unknown
CVE-2005-0576
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
0
Attacker Value
Unknown
CVE-2005-0816
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
0
Attacker Value
Unknown
CVE-2004-0790
Disclosure Date: April 12, 2005 (last updated February 22, 2025)
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
0
Attacker Value
Unknown
CVE-2004-0791
Disclosure Date: April 12, 2005 (last updated February 22, 2025)
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
0
Attacker Value
Unknown
CVE-2005-0109
Disclosure Date: March 05, 2005 (last updated February 22, 2025)
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
0
Attacker Value
Unknown
CVE-2004-0481
Disclosure Date: February 23, 2005 (last updated February 22, 2025)
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
0
Attacker Value
Unknown
CVE-2005-0447
Disclosure Date: February 15, 2005 (last updated February 22, 2025)
Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.
0
Attacker Value
Unknown
CVE-2004-1394
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
0