
CVE-2004-0360 – Solaris 8/9 passwd - 'circ()' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2004-0360
18 Mar 2004 — Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors. • https://www.exploit-db.com/exploits/715 •

CVE-2004-1359
https://notcve.org/view.php?id=CVE-2004-1359
04 Mar 2004 — Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user. • http://sunsolve.sun.com/search/document.do?assetkey=1-26-57508-1 •

CVE-2004-1360
https://notcve.org/view.php?id=CVE-2004-1360
27 Feb 2004 — Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files. • http://secunia.com/advisories/10991 •

CVE-2004-1082
https://notcve.org/view.php?id=CVE-2004-1082
03 Feb 2004 — mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. • http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html •

CVE-2003-1066
https://notcve.org/view.php?id=CVE-2003-1066
31 Dec 2003 — Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets. • http://secunia.com/advisories/8944 •

CVE-2003-1076
https://notcve.org/view.php?id=CVE-2003-1076
31 Dec 2003 — Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file. • http://secunia.com/advisories/8235 •

CVE-2003-1082
https://notcve.org/view.php?id=CVE-2003-1082
31 Dec 2003 — Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068. • http://secunia.com/advisories/7892 •

CVE-2003-1073 – Sun Solaris 2.5/2.6/7.0/8/9 AT Command - Arbitrary File Deletion
https://notcve.org/view.php?id=CVE-2003-1073
31 Dec 2003 — A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place. • https://www.exploit-db.com/exploits/22203 •

CVE-2003-0999
https://notcve.org/view.php?id=CVE-2003-0999
17 Dec 2003 — Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files. Múltiples vulnerabilidades desconocidas en lpstat y la librería libprint en Solaris 2.6 a 9 puede permitir a atacantes ejecutar código arbitrario o leer o escribir ficheros arbitrarios. • http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/57451 •

CVE-2003-1056
https://notcve.org/view.php?id=CVE-2003-1056
11 Dec 2003 — The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files. • http://secunia.com/advisories/10411 •