Show plain JSON{"id": "CVE-2004-2686", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.2, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": true, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2004-12-31T05:00:00.000", "references": [{"url": "http://seclists.org/bugtraq/2004/Apr/0081.html", "source": "cve@mitre.org"}, {"url": "http://securitytracker.com/id?1008833", "tags": ["Patch"], "source": "cve@mitre.org"}, {"url": "http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2004-04/0297.html", "source": "cve@mitre.org"}, {"url": "http://www.immunitysec.com/downloads/solaris_kernel_vfs.sxw.pdf", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/9962", "tags": ["Exploit", "Patch"], "source": "cve@mitre.org"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1381", "source": "cve@mitre.org"}, {"url": "http://seclists.org/bugtraq/2004/Apr/0081.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securitytracker.com/id?1008833", "tags": ["Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2004-04/0297.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.immunitysec.com/downloads/solaris_kernel_vfs.sxw.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/9962", "tags": ["Exploit", "Patch"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1381", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-22"}]}], "descriptions": [{"lang": "en", "value": "Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure."}], "lastModified": "2025-04-03T01:03:51.193", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:sun:solaris:2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34EBF074-78C8-41AF-88F1-DA6726E56F8B"}, {"criteria": "cpe:2.3:o:sun:solaris:7.0:*:x86:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F1F312C-413F-4DB4-ABF4-48E33F6FECF2"}, {"criteria": "cpe:2.3:o:sun:solaris:8.0:*:x86:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1894C542-AA81-40A9-BF47-AE24C93C1ACB"}, {"criteria": "cpe:2.3:o:sun:solaris:9.0:*:x86:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B837BB7-5F62-4CD5-9C64-8553C28EA8A7"}, {"criteria": "cpe:2.3:o:sun:sunos:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "369207B4-96FA-4324-9445-98FAE8ECF5DB"}, {"criteria": "cpe:2.3:o:sun:sunos:5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08003947-A4F1-44AC-84C6-9F8D097EB759"}, {"criteria": "cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A2475113-CFE4-41C8-A86F-F2DA6548D224"}, {"criteria": "cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1E585DC-FC74-4BB0-96B7-C00B6DB610DF"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}