Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv01 through snv111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.
Unspecified vulnerability in Sun OpenSolaris snv39 through snv45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufsgetpage and (2) ufsputapage routines, aka CR 6442712.
Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv86 through snv91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufsgetpage and (2) ufsputapage routines, aka CR 6679732.
Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv01 through snv108 allows local users to cause a denial of service (system panic) via unknown vectors related to PFKEY socket, probably related to setting socket options.
The NFS server in Sun Solaris 10, and OpenSolaris before snv111, does not properly implement the AUTHNONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTHNONE and AUTHSYS security modes.
The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4opreaddir function.
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."
Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the doorcall function.
Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.
The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv01 though snv85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
libike in Sun Solaris 9 and 10, and OpenSolaris before snv100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
The UFS implementation in the kernel in Sun OpenSolaris snv29 through snv90 allows local users to cause a denial of service (panic) via the single posixfallocate test in the SUSv3 POSIX test suite, related to an FALLOCSP fcntl call.
Unspecified vulnerability in the nfs4renamepersistentfh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv102 allows local users to cause a denial of service (recursive mutexenter and panic) via unspecified vectors.
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the portdissociate and close functions.
Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.
Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.