Back

CVE-2004-2686

Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (8)

Vendor Product Version
sun solaris 2.6
sun solaris 7.0
sun solaris 8.0
sun solaris 9.0
sun sunos -
sun sunos 5.7
sun sunos 5.8
sun sunos 5.9

GitHub Security Advisory GHSA-w8j7-864p-92c6

Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 1.17%

Top 35% most likely to be exploited

Threat Score 29.2 / 100

Data Sources

NVD EPSS GitHub