Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1296 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.
CVE-2010-4450 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 3.7 LOW N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Solaris and Linux; 5.0 Update 27 and earlier for Solaris and Linux; and 1.4.2_29 and earlier for Solaris and Linux allows local standalone applications to affect confidentiality, integrity, and availability via unknown vectors related to Launcher. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is an untrusted search path vulnerability involving an empty LD_LIBRARY_PATH environment variable.
CVE-2010-4462 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 10.0 HIGH N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-4454 and CVE-2010-4473.
CVE-2001-0124 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
CVE-2001-0115 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
CVE-2010-4469 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 10.0 HIGH N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is heap corruption related to the Verifier and "backward jsrs."
CVE-2010-4447 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 4.3 MEDIUM N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than CVE-2010-4475.
CVE-1999-0786 1 Sun 2 Solaris, Sunos 2018-10-30 4.6 MEDIUM N/A
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
CVE-2001-0059 1 Sun 1 Sunos 2018-10-30 6.2 MEDIUM N/A
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
CVE-2003-1060 1 Sun 2 Solaris, Sunos 2018-10-30 5.0 MEDIUM N/A
The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.
CVE-1999-0078 10 Bsdi, Freebsd, Hp and 7 more 11 Bsd Os, Freebsd, Hp-ux and 8 more 2018-10-30 1.9 LOW N/A
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
CVE-1999-0773 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Solaris lpset program allows local users to gain root access.
CVE-2007-5240 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 5.0 MEDIUM N/A
Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.
CVE-2007-5274 3 Mozilla, Opera, Sun 5 Firefox, Opera Browser, Jdk and 2 more 2018-10-30 2.6 LOW N/A
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.
CVE-2010-4448 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 2.6 LOW N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Networking. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves "DNS cache poisoning by untrusted applets."
CVE-2010-4465 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 10.0 HIGH N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the lack of framework support by AWT event dispatch, and/or "clipboard access in Applets."
CVE-2011-0815 1 Sun 2 Jdk, Jre 2018-10-30 10.0 HIGH N/A
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to AWT.
CVE-1999-0767 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
CVE-2007-0243 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 6.8 MEDIUM N/A
Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.
CVE-1999-0069 1 Sun 1 Sunos 2018-10-30 7.2 HIGH N/A
Solaris ufsrestore buffer overflow.
CVE-1999-0190 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
CVE-2000-0949 2 Lbl, Sun 2 Lbl Traceroute, Sunos 2018-10-30 7.2 HIGH N/A
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
CVE-2000-0844 13 Caldera, Conectiva, Debian and 10 more 16 Openlinux, Openlinux Ebuilder, Openlinux Eserver and 13 more 2018-10-30 10.0 HIGH N/A
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
CVE-1999-0696 2 Hp, Sun 3 Hp-ux, Solaris, Sunos 2018-10-30 10.0 HIGH N/A
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
CVE-1999-0189 1 Sun 2 Solaris, Sunos 2018-10-30 7.5 HIGH N/A
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
CVE-1999-0691 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2018-10-30 7.2 HIGH N/A
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
CVE-2006-5012 1 Sun 2 Solaris, Sunos 2018-10-30 6.6 MEDIUM N/A
Unspecified vulnerability in Sun Solaris 8, 9, and 10 before 20060925 allows local users to cause a denial of service (disable syslog) and prevent security messages from being logged via unspecified vectors.
CVE-2005-1518 1 Sun 2 Solaris, Sunos 2018-10-30 2.1 LOW N/A
Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.
CVE-1999-0689 2 Cde, Sun 3 Cde, Solaris, Sunos 2018-10-30 7.2 HIGH N/A
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
CVE-2000-0471 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.
CVE-1999-0687 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2018-10-30 7.5 HIGH N/A
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVE-1999-0188 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
The passwd command in Solaris can be subjected to a denial of service.
CVE-2007-5232 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 4.0 MEDIUM N/A
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.
CVE-1999-0676 1 Sun 2 Solaris, Sunos 2018-10-30 4.6 MEDIUM N/A
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVE-2000-0407 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
CVE-1999-0023 6 Bsdi, Freebsd, Ibm and 3 more 10 Bsd Os, Freebsd, Aix and 7 more 2018-10-30 7.2 HIGH N/A
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
CVE-2000-0337 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.
CVE-1999-0674 3 Netbsd, Openbsd, Sun 4 Netbsd, Openbsd, Solaris and 1 more 2018-10-30 7.2 HIGH N/A
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
CVE-1999-0065 1 Sun 2 Solaris, Sunos 2018-10-30 7.5 HIGH N/A
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
CVE-2005-0816 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
CVE-2000-0317 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.
CVE-2000-0316 1 Sun 2 Solaris, Sunos 2018-10-30 7.2 HIGH N/A
Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.
CVE-2002-0679 6 Caldera, Compaq, Hp and 3 more 8 Openunix, Unixware, Tru64 and 5 more 2018-10-30 10.0 HIGH N/A
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.
CVE-1999-0185 1 Sun 2 Solaris, Sunos 2018-10-30 7.5 HIGH N/A
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
CVE-2002-0678 7 Caldera, Compaq, Hp and 4 more 9 Openunix, Unixware, Tru64 and 6 more 2018-10-30 7.2 HIGH N/A
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
CVE-2004-0654 1 Sun 2 Solaris, Sunos 2018-10-30 2.1 LOW N/A
Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).
CVE-2004-0790 2 Microsoft, Sun 8 Windows 2000, Windows 2003 Server, Windows 98 and 5 more 2018-10-30 5.0 MEDIUM N/A
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.
CVE-2004-0481 1 Sun 2 Solaris, Sunos 2018-10-30 2.1 LOW N/A
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
CVE-2002-0677 7 Caldera, Compaq, Hp and 4 more 9 Openunix, Unixware, Tru64 and 6 more 2018-10-30 7.5 HIGH N/A
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
CVE-2007-3698 1 Sun 3 Jdk, Jre, Sdk 2018-10-30 7.8 HIGH N/A
The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.