| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. |
| DNS cache poisoning via BIND, by predictable query IDs. |
| Buffer overflows in Sun libnsl allow root access. |
| Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands. |
| pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. |
| Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root. |
| vold in Solaris 2.x allows local users to gain root access. |
| The passwd command in Solaris can be subjected to a denial of service. |
| The SunView (SunTools) selection_svc facility allows remote users to read files. |
| Denial of service by sending forged ICMP unreachable packets. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack. |
| nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers. |
| Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames. |
| Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable. |
| Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391. |
| Solaris ff.core allows local users to modify files. |
| rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd. |
| MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference. |
| Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd). |