Page 25 of 559 results (0.022 seconds)

CVSS: 6.9EPSS: 0%CPEs: 6EXPL: 0

Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files. Sun SNMP Management Agent (SUNWmasf) v1.4u2 a la v1.5.4, permite a usuarios locales sobrescribir ficheros de su elección y obtener privilegios a través de un ataque de enlace simbólico sobre ficheros temporales. • http://osvdb.org/50987 http://secunia.com/advisories/33328 http://sunsolve.sun.com/search/document.do?assetkey=1-26-248646-1 http://www.securityfocus.com/bid/33014 http://www.securitytracker.com/id?1021496 https://exchange.xforce.ibmcloud.com/vulnerabilities/47619 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 4.6EPSS: 0%CPEs: 112EXPL: 0

The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv_50 through snv_104 does not properly check permissions, which allows local users to gain privileges and obtain sensitive information via unspecified vectors. El Demonio de Caché del Servicio de Nombres (ncsd) en Sun Solaris 10 y OpenSolaris snv_50 hasta snv_104 no comprueba adecuadamente los permisos, esto permite a usuarios locales obtener privilegios e información sensible a través de vectores no especificados. • http://osvdb.org/50934 http://secunia.com/advisories/33218 http://securitytracker.com/id?1021477 http://sunsolve.sun.com/search/document.do?assetkey=1-26-242006-1 http://www.securityfocus.com/bid/32921 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 1%CPEs: 91EXPL: 0

Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session). Una vulnerabilidad sin especificar en el X Inter Client Exchange library (tambien llamado libICE) en Sun Solaris 8 a 10 y en versiones de OpenSolaris anteriores a la snv_85, permite atacantes dependientes de contexto causar una denegación de servicio (mediante un fallo de aplicación), como lo demuestra un escaneo de puertos que desencadena una violación de segmento en el Gnome Session Manager(alias gnome-session). • http://secunia.com/advisories/33157 http://secunia.com/advisories/33325 http://securitytracker.com/id?1021391 http://sunsolve.sun.com/search/document.do?assetkey=1-21-119067-11-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-243566-1 http://support.avaya.com/elmodocs2/security/ASA-2008-513.htm http://www.securityfocus.com/bid/32807 http://www.vupen.com/english/advisories/2008/3431 https://exchange.xforce.ibmcloud.com/vulnerabilities/47311 https://oval.cisecurity.org&#x • CWE-399: Resource Management Errors •

CVSS: 7.2EPSS: 0%CPEs: 160EXPL: 2

tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference. Tun en IP Tunnel en Solaris 10 y OpenSolaris snv_01 a snv_76 permite a usuarios locales causar una denegación de servicio (causando un panic del sistema) y, posiblemente, ejecutar código arbitrario a través de una solicitud SIOCGTUNPARAM IOCTL modificada, que ocasiona una desreferencia a un puntero NULL. • https://www.exploit-db.com/exploits/15962 http://secunia.com/advisories/33160 http://securityreason.com/securityalert/4801 http://sunsolve.sun.com/search/document.do?assetkey=1-26-242266-1 http://www.exploit-db.com/exploits/15962 http://www.securityfocus.com/archive/1/499352/100/0/threaded http://www.securityfocus.com/bid/32904 http://www.securitytracker.com/id?1021464 http://www.trapkit.de/advisories/TKADV2008-015.txt http://www.vupen.com/english/advisories/2008/3454 https& • CWE-399: Resource Management Errors •

CVSS: 2.1EPSS: 0%CPEs: 210EXPL: 0

The Kerberos credential renewal feature in Sun Solaris 8, 9, and 10, and OpenSolaris build snv_01 through snv_104, allows local users to cause a denial of service (authentication failure) via unspecified vectors related to incorrect cache file permissions, and lack of credential storage by the store_cred function in pam_krb5. La funcionalidad de renovación de credenciales de Kerberos en Sun Solaris versiones 8, 9 y 10, y OpenSolaris build snv_01 hasta snv_104, permite a usuarios locales causar una denegación de servicio (fallo de autenticación) por medio de vectores no especificados relacionados con permisos incorrectos de archivos de caché y falta de almacenamiento de credenciales por parte de la función store_cred en pam_krb5. • http://secunia.com/advisories/33042 http://secunia.com/advisories/33313 http://sunsolve.sun.com/search/document.do?assetkey=1-21-112908-33-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-244866-1 http://support.avaya.com/elmodocs2/security/ASA-2008-515.htm http://www.securityfocus.com/bid/32793 http://www.securitytracker.com/id?1021390 http://www.vupen.com/english/advisories/2008/3428 https://exchange.xforce.ibmcloud.com/vulnerabilities/47291 https://oval.cisecurity • CWE-255: Credentials Management Errors •