Sunos

Vendor:

First CVE: Jul 26, 1989 · Active for 36 years

609
Total CVEs
More Total CVEs than 100% of tracked products
23.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sunos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 1989
36 years ago
Most Recent CVE
Jan 21, 2015
4,202 days ago

CVE Severity & Scoring

Sunos609 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (0.7%)
Network1 (0.2%)
Unknown603 (99.0%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low6 (1.0%)
High0 (0.0%)
Unknown603 (99.0%)
User Interaction
None6 (1.0%)
Unknown603 (99.0%)
Required0 (0.0%)
Privileges Required
Low1 (0.2%)
High0 (0.0%)
None5 (0.8%)
Unknown603 (99.0%)

Top CVEs

Signals from CVEs in this product scope (609 CVEs).

609 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the
Feb 12, 200710.091NOYES
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.
Aug 10, 201110.090NOYES
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a
Jun 16, 201110.089NOYES
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to
May 5, 200310.088NOYES
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when l
Dec 31, 200110.088NOYES
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as
Dec 12, 200110.088NOYES
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a
Mar 7, 200310.080NOYES
Land IP denial of service.
Dec 1, 19975.079NOYES
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
May 3, 200110.078NOYES
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC
Jun 10, 200810.077NOYES

Exploit Exposure

Signals from CVEs in this product scope (609 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
14 CVEs
2.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
117 CVEs
19.2% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (609 CVEs).

Media Mentions

Signals from CVEs in this product scope (609 CVEs).

Top CNAs Publishing CVEs For Sunos

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.9845.32.2%06
5.82125.96.1%043
5.71466.57.9%060
5.686.15.3%01
5.5.11126.98.8%053
5.5846.97.4%042
5.4747.28.2%033
5.3537.46.3%021
5.2147.712.4%08
5.111264.92.0%02
5.101565.22.1%06
5.1127.814.5%08
5.0216.99.8%011
4.1psr_a36.10.7%00
4.1.4jl27.21.2%01
4.1.4256.89.1%010
4.1.3u1197.111.6%07
4.1.3c97.01.3%00
4.1.3a115.01.4%00
4.1.3237.02.7%08