CVE-2009-0268
https://notcve.org/view.php?id=CVE-2009-0268
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl. Una condición de carrera en el pseudo-terminal (alias PTY) en el módulo controlador de Sun Solaris 8 a 10, y OpenSolaris en versiones anteriores a la snv_103, permite a usuarios locales provocar una denegación de servicio (con un panic del kernel) a través de vectores no especificados relacionados con la falta de "código correctamente secuenciado" en PTC y PTSL. • http://secunia.com/advisories/33708 http://sunsolve.sun.com/search/document.do?assetkey=1-21-113685-07-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-249586-1 http://support.avaya.com/elmodocs2/security/ASA-2009-034.htm http://www.securityfocus.com/bid/33406 http://www.securitytracker.com/id?1021640 https://exchange.xforce.ibmcloud.com/vulnerabilities/48179 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6061 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2009-0132
https://notcve.org/view.php?id=CVE-2009-0132
Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument). Desbordamiento de entero en la función aio_suspend en Sun Solaris v8 hasta la v10 y OpenSolaris cuando el modo 32-bit esta activado, permitiendo a usuarios locales causar una denegación de servicio (causando un panic) a través de un valor de entero largo en el segundo argumento (anteriormente conocido como argumento "nent"). • http://secunia.com/advisories/33516 http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-247986-1 http://www.securityfocus.com/bid/33188 http://www.securitytracker.com/id?1021553 http://www.trapkit.de/advisories/TKADV2009-001.txt http://www.vupen.com/english/advisories/2009/0099 • CWE-189: Numeric Errors •
CVE-2008-5746
https://notcve.org/view.php?id=CVE-2008-5746
Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files. Sun SNMP Management Agent (SUNWmasf) v1.4u2 a la v1.5.4, permite a usuarios locales sobrescribir ficheros de su elección y obtener privilegios a través de un ataque de enlace simbólico sobre ficheros temporales. • http://osvdb.org/50987 http://secunia.com/advisories/33328 http://sunsolve.sun.com/search/document.do?assetkey=1-26-248646-1 http://www.securityfocus.com/bid/33014 http://www.securitytracker.com/id?1021496 https://exchange.xforce.ibmcloud.com/vulnerabilities/47619 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2008-5684
https://notcve.org/view.php?id=CVE-2008-5684
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session). Una vulnerabilidad sin especificar en el X Inter Client Exchange library (tambien llamado libICE) en Sun Solaris 8 a 10 y en versiones de OpenSolaris anteriores a la snv_85, permite atacantes dependientes de contexto causar una denegación de servicio (mediante un fallo de aplicación), como lo demuestra un escaneo de puertos que desencadena una violación de segmento en el Gnome Session Manager(alias gnome-session). • http://secunia.com/advisories/33157 http://secunia.com/advisories/33325 http://securitytracker.com/id?1021391 http://sunsolve.sun.com/search/document.do?assetkey=1-21-119067-11-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-243566-1 http://support.avaya.com/elmodocs2/security/ASA-2008-513.htm http://www.securityfocus.com/bid/32807 http://www.vupen.com/english/advisories/2008/3431 https://exchange.xforce.ibmcloud.com/vulnerabilities/47311 https://oval.cisecurity.org • CWE-399: Resource Management Errors •
CVE-2008-5690
https://notcve.org/view.php?id=CVE-2008-5690
The Kerberos credential renewal feature in Sun Solaris 8, 9, and 10, and OpenSolaris build snv_01 through snv_104, allows local users to cause a denial of service (authentication failure) via unspecified vectors related to incorrect cache file permissions, and lack of credential storage by the store_cred function in pam_krb5. La funcionalidad de renovación de credenciales de Kerberos en Sun Solaris versiones 8, 9 y 10, y OpenSolaris build snv_01 hasta snv_104, permite a usuarios locales causar una denegación de servicio (fallo de autenticación) por medio de vectores no especificados relacionados con permisos incorrectos de archivos de caché y falta de almacenamiento de credenciales por parte de la función store_cred en pam_krb5. • http://secunia.com/advisories/33042 http://secunia.com/advisories/33313 http://sunsolve.sun.com/search/document.do?assetkey=1-21-112908-33-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-244866-1 http://support.avaya.com/elmodocs2/security/ASA-2008-515.htm http://www.securityfocus.com/bid/32793 http://www.securitytracker.com/id?1021390 http://www.vupen.com/english/advisories/2008/3428 https://exchange.xforce.ibmcloud.com/vulnerabilities/47291 https://oval.cisecurity • CWE-255: Credentials Management Errors •