← Vulnerability feed

Vulnerability record · CVE-1999-0209 · published 14 August 1990

CVE-1999-0209: SunView selection_svc allows remote file reading

Sun · Sunos

The SunView (SunTools) selection_svc facility in SunOS permits remote users to read files. This is an information disclosure flaw in a legacy Sun windowing service. Because the service is reachable over the network without authentication, exposed systems can leak file contents to anyone who can reach the port.

5.0 CVSS 2.0 Medium EPSS 49% · top 1.2%
5.0CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

The SunView (SunTools) selection_svc facility allows remote users to read files.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated information disclosure with a high EPSS percentile, though the record is old and lacks exploit confirmation.

What it is

The SunView (SunTools) selection_svc facility in SunOS permits remote users to read files. This is an information disclosure flaw in a legacy Sun windowing service. Because the service is reachable over the network without authentication, exposed systems can leak file contents to anyone who can reach the port.

Impact

An attacker gains read access to files on the host, potentially exposing sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network (AV:N) with low complexity and no authentication required (Au:N). No user interaction is indicated by the vector or description.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high at 0.4853 (98.8th percentile), indicating elevated predicted exploitation activity.

What to do

  • Patch or upgrade SunOS to a version where the selection_svc issue is fixed; if no fix is available, retire or isolate the affected system.
  • Disable the SunView/SunTools selection_svc service if it is not required.
  • Block network access to the selection_svc port at the host and network firewall.
  • Segment legacy SunOS hosts so they cannot be reached from untrusted networks.
  • Monitor for and decommission end-of-life SunOS systems that cannot be patched.

Detection

  • Monitor network traffic to the selection_svc port for unexpected remote connections.
  • Audit SunOS hosts for the selection_svc process and confirm whether it is running.
  • Review host logs for file access patterns consistent with remote reads via the service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-0209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4435Sunos vulnerabilityUnspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to C…EPSS 14%10.0CVE-2008-4619Sunos vulnerabilityThe RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in progra…EPSS 12%10.0CVE-2008-2144Sunos vulnerabilityMultiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or exe…EPSS 16%10.0CVE-2008-1369Sunos permissions and access controls vulnerabilityA certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that confi…EPSS 2.6%10.0CVE-2007-3093Sun solaris vulnerabilityUnspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote atta…EPSS 4.7%10.0CVE-2007-0882Solaris telnet daemon argument injection bypasses authenticationThe telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request…EPSS 98%analysed10.0CVE-2004-1351Sun solaris vulnerabilityUnknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.EPSS 6.0%10.0CVE-2004-0523Mit kerberos vulnerabilityMultiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as …EPSS 12%

Source: NIST National Vulnerability Database (record CVE-1999-0209), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.