Page 6 of 174 results (0.007 seconds)

CVSS: 5.5EPSS: 0%CPEs: 4EXPL: 1

31 Dec 1999 — lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times. • http://ciac.llnl.gov/ciac/bulletins/e-25.shtml •

CVSS: 10.0EPSS: 0%CPEs: 5EXPL: 0

31 Dec 1999 — Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586. • http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1 •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

31 Dec 1999 — The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges. • http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1 •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

31 Dec 1999 — loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584. • http://www.cert.org/advisories/CA-1995-12.html •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

31 Dec 1999 — Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129. • http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1 •

CVSS: 10.0EPSS: 14%CPEs: 9EXPL: 5

10 Dec 1999 — Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. • https://www.exploit-db.com/exploits/19668 •

CVSS: 10.0EPSS: 1%CPEs: 11EXPL: 0

09 Dec 1999 — Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service. • http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/190 •

CVSS: 10.0EPSS: 3%CPEs: 11EXPL: 1

07 Dec 1999 — Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode. • https://www.exploit-db.com/exploits/19663 •

CVSS: 5.5EPSS: 0%CPEs: 7EXPL: 1

01 Dec 1999 — Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack. • https://www.exploit-db.com/exploits/19235 •

CVSS: 5.5EPSS: 0%CPEs: 7EXPL: 1

01 Dec 1999 — Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly. • https://www.exploit-db.com/exploits/19232 •