
CVE-2000-0844 – Immunix OS 6.2 - LC glibc format string
https://notcve.org/view.php?id=CVE-2000-0844
14 Nov 2000 — Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/20187 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2000-0471 – Solaris 2.5/2.6/7.0/8 ufsrestore - Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2000-0471
14 Jun 2000 — Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname. • https://www.exploit-db.com/exploits/20014 •

CVE-2000-0407 – Solaris 2.6/7.0/8 - 'netpr' Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2000-0407
12 May 2000 — Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option. • https://www.exploit-db.com/exploits/19910 •

CVE-2000-0317 – Solaris 2.6/7.0 - 'lpset -r' Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2000-0317
24 Apr 2000 — Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option. • https://www.exploit-db.com/exploits/19872 •

CVE-2000-0055
https://notcve.org/view.php?id=CVE-2000-0055
06 Jan 2000 — Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option. • http://www.securityfocus.com/bid/918 •

CVE-1999-0977 – Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-1999-0977
10 Dec 1999 — Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. • https://www.exploit-db.com/exploits/19668 •

CVE-1999-0974
https://notcve.org/view.php?id=CVE-1999-0974
09 Dec 1999 — Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service. • http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/190 •

CVE-1999-0973 – Solaris 2.3/2.4/2.5/2.5.1/2.6/7.0 snoop - 'print_domain_name' Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-1999-0973
07 Dec 1999 — Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode. • https://www.exploit-db.com/exploits/19663 •

CVE-1999-0860 – Solaris 7.0 - 'chkperm' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0860
01 Dec 1999 — Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack. • https://www.exploit-db.com/exploits/19235 •

CVE-1999-0859 – SunOS 4.1.4 - arp(8c) Memory Dump
https://notcve.org/view.php?id=CVE-1999-0859
01 Dec 1999 — Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly. • https://www.exploit-db.com/exploits/19232 •