Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."
The NFS server in Sun Solaris 10, and OpenSolaris before snv111, does not properly implement the AUTHNONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTHNONE and AUTHSYS security modes.
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."
Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris before snv37, when automountd is used, allows user-assisted remote attackers to cause a denial of service (unresponsive NFS filesystems) via unknown vectors.
libike in Sun Solaris 9 and 10, and OpenSolaris before snv100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the doorcall function.
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv01 though snv85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
Unspecified vulnerability in the nfs4renamepersistentfh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv102 allows local users to cause a denial of service (recursive mutexenter and panic) via unspecified vectors.
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the portdissociate and close functions.
The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.
Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.
The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4opreaddir function.
Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv01 through snv108 allows local users to cause a denial of service (system panic) via unknown vectors related to PFKEY socket, probably related to setting socket options.
Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv01 through snv111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.