HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opcop account, which allows remote attackers to execute arbitrary code via unspecified vectors.
Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011- and 120012- patches, allows remote attackers to bypass certain netgroup restrictions and obtain root access to a filesystem via NFS requests from a client root user.