CVE-2008-3870
https://notcve.org/view.php?id=CVE-2008-3870
Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation. Desbordamiento de entero en sadmind en Sun Solaris v8 y v9 permite a atacantes remotos ejecutar código de forma arbitraria a través de una petición RPC manipulada que inicia un desbordamiento de búfer basado en montículo, relacionado con una localización de memoria no adecuada. • http://secunia.com/advisories/32473 http://secunia.com/advisories/35191 http://secunia.com/secunia_research/2008-47 http://sunsolve.sun.com/search/document.do?assetkey=1-21-116455-02-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-259468-1 http://support.avaya.com/elmodocs2/security/ASA-2009-195.htm http://www.osvdb.org/54668 http://www.securityfocus.com/archive/1/503772/100/0/threaded http://www.securityfocus.com/bid/35083 http://www.securitytracker.com/ • CWE-189: Numeric Errors •
CVE-2008-3869
https://notcve.org/view.php?id=CVE-2008-3869
Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters. Desbordamiento de búfer basado en entero en sadmind en Sun Solaris v8 y v9 permite a atacantes remotos ejecutar código de forma arbitraria a través de unas peticiones RPC manipuladas, relacionado con la decodificación inadecuada de parámetros "request". • http://secunia.com/advisories/32473 http://secunia.com/advisories/35191 http://secunia.com/secunia_research/2008-45 http://sunsolve.sun.com/search/document.do?assetkey=1-21-116455-02-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-259468-1 http://support.avaya.com/elmodocs2/security/ASA-2009-195.htm http://www.osvdb.org/54663 http://www.securityfocus.com/archive/1/503771/100/0/threaded http://www.securityfocus.com/bid/35083 http://www.securitytracker.com/ • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-1673
https://notcve.org/view.php?id=CVE-2009-1673
The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD. El Kernel en Sun Solaris v9 permite a usuarios locales provocar una denegación de servicio (panic) llamando a fstat con un primer argumento de AT_FDCWD. • http://osvdb.org/54464 http://secunia.com/advisories/35103 http://secunia.com/advisories/35119 http://sunsolve.sun.com/search/document.do?assetkey=1-21-122300-40-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-257988-1 http://support.avaya.com/elmodocs2/security/ASA-2009-188.htm http://www.securityfocus.com/bid/34979 http://www.securitytracker.com/id?1022232 http://www.vupen.com/english/advisories/2009/1315 http://www.vupen.com/english/advisories/2009/1388 •
CVE-2009-1478 – Solaris 10 / OpenSolaris - 'dtrace' Local Kernel Denial of Service (PoC)
https://notcve.org/view.php?id=CVE-2009-1478
Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors. Múltiples vulnerabilidades no especificadas en los manipuladores DTrace ioctl en Sun Solaris v10 y OpenSolaris anteriores a snv_114, permiten a usuarios locales provocar una denegación de servicio (panic) a través de vectores desconocidos. • https://www.exploit-db.com/exploits/8597 http://osvdb.org/54138 http://secunia.com/advisories/34836 http://secunia.com/advisories/35098 http://sunsolve.sun.com/search/document.do?assetkey=1-66-257708-1 http://support.avaya.com/elmodocs2/security/ASA-2009-171.htm http://www.securityfocus.com/bid/34753 http://www.securitytracker.com/id?1022143 http://www.vupen.com/english/advisories/2009/1199 http://www.vupen.com/english/advisories/2009/1378 https://exchange.xforce.ibm •
CVE-2009-1276
https://notcve.org/view.php?id=CVE-2009-1276
XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications. XScreenSaver en Sun Solaris v10 and OpenSolaris anteriores a snv_109, y Solaris v8 y v9 con GNOME v2.0 o v2.0.2, permite a atacantes próximos físicamente conseguir información sensible, leyendo las ventanas "PopUp"s, que se muestran cuando la pantalla se bloquea, como se demostró en las notificaciones de nuevo mensaje de Thunderbird. • http://securitytracker.com/id?1022009 http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-22-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-255308-1 http://www.securityfocus.com/bid/34421 http://www.vupen.com/english/advisories/2009/0978 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •