| OSVDB ID | Disclosure Date | Title |
|
88790
Description:
ConvexOS contains a flaw that leads to unauthorized privileges being gained. The issue is due to vnode ops not properly distinguishing between regular files and device types. This may allow an attacker to modify the characteristics of a vnode, which will allow the attacker to gain escalated privileges.
|
1990-12-20
|
ConvexOS NFS Writeable Device vnode Manipulation Privilege Escalation
|
|
6606
Description:
(Description Provided by CVE) : TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.
|
1990-12-20
|
SunOS TIOCCONS Local Privilege Escalation
|
|
88789
Description:
SunOS contains a flaw that leads to unauthorized privileges being gained. The issue is due to vnode ops not properly distinguishing between regular files and device types. This may allow an attacker to modify the characteristics of a vnode, which will allow the attacker to gain escalated privileges.
|
1990-12-20
|
SunOS NFS Writeable Device vnode Manipulation Privilege Escalation
|
|
88788
Description:
Rand Mail Handler is prone to a flaw in the way it loads dynamic-link libraries (DLL). The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program will load it before the legitimate version. This allows a local attacker to inject custom code that will be run with the privilege of the program or user executing the program. This attack can be leveraged remotely in some cases by placing the malicious file or library on a network share or extracted archive downloaded from a remote source. This can be done by tricking a user into opening an unspecified file from the local file system or a USB drive in some cases. This attack scenario is certainly possible, but rare.
|
1990-12-19
|
Rand Mail Handler Multiple Utility Path Subversion Local Privilege Escalation
|
|
84092
Description:
Microport Unix contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error occurs in /dev/mem that allows an attacker to manipulate IOCTLs to execute 386 I/O instructions. This may allow a local attacker to gain escalated privileges.
|
1990-12-11
|
Microport Unix /dev/mem IOCTL Manipulation Local Privilege Escalation
|
|
88787
Description:
SunOS contains a flaw in the RPC portmapper. This issue may allow an attacker to delete arbitrary services, in order to disable services such as NFS or yp.
|
1990-12-05
|
SunOS RPC portmapper Remote Service Manipulation
|