Unspecified vulnerability in Sun Solaris 10 and OpenSolaris snv49 through snv117, when 64bit mode is used on the Intel x86 platform and a Linux (lx) branded zone is configured, allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2007-6225.
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the portdissociate and close functions.
Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.
Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.
Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv01 through snv111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.
Unspecified vulnerability in Sun OpenSolaris snv39 through snv45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufsgetpage and (2) ufsputapage routines, aka CR 6442712.
Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv86 through snv91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufsgetpage and (2) ufsputapage routines, aka CR 6679732.
Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv47 through snv85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufsgetpage and (2) ufsputapage routines, aka CR 6425723.
Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv01 through snv108 allows local users to cause a denial of service (system panic) via unknown vectors related to PFKEY socket, probably related to setting socket options.
Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the doorcall function.
Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.
The NFS server in Sun Solaris 10, and OpenSolaris before snv111, does not properly implement the AUTHNONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTHNONE and AUTHSYS security modes.
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."
The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4opreaddir function.
The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.
The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv01 though snv85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.
Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."
Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
libike in Sun Solaris 9 and 10, and OpenSolaris before snv100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.
Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv61 through snv106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."
Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv61 through snv106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.
The UFS implementation in the kernel in Sun OpenSolaris snv29 through snv90 allows local users to cause a denial of service (panic) via the single posixfallocate test in the SUSv3 POSIX test suite, related to an FALLOCSP fcntl call.
Unspecified vulnerability in the nfs4renamepersistentfh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv102 allows local users to cause a denial of service (recursive mutexenter and panic) via unspecified vectors.
The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv50 through snv104 does not properly check permissions, which allows local users to gain privileges and obtain sensitive information via unspecified vectors.
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv47 through snv82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.