The dynamic linker in Solaris allows a local user to create arbitrary files via the LDPROFILE environmental variable and a symlink attack.
sdtcmconvert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Buffer overflow in SGI IRIX mailx program.
Sun's ftpd daemon can be subjected to a denial of service.
DNS cache poisoning via BIND, by predictable query IDs.
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.