Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0345 4 Freebsd, Ibm, Sco and 1 more 7 Freebsd, Aix, Sng and 4 more 2008-09-09 5.0 MEDIUM N/A
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
CVE-1999-0321 1 Sun 1 Solaris 2008-09-09 7.2 HIGH N/A
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
CVE-1999-0298 2 Slackware, Sun 2 Slackware Linux, Sunos 2008-09-09 7.5 HIGH N/A
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.
CVE-1999-0254 1 Sun 1 Solaris 2008-09-09 10.0 HIGH N/A
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.
CVE-1999-0217 1 Sun 1 Sunos 2008-09-09 5.0 MEDIUM N/A
Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.
CVE-1999-0214 1 Sun 1 Sunos 2008-09-09 10.0 HIGH N/A
Denial of service by sending forged ICMP unreachable packets.
CVE-1999-0209 1 Sun 1 Sunos 2008-09-09 5.0 MEDIUM N/A
The SunView (SunTools) selection_svc facility allows remote users to read files.
CVE-1999-0168 1 Sun 1 Sunos 2008-09-09 7.5 HIGH N/A
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.
CVE-1999-0057 5 Eric Allman, Freebsd, Hp and 2 more 7 Vacation, Freebsd, Hp-ux and 4 more 2008-09-09 7.5 HIGH N/A
Vacation program allows command execution by remote users through a sendmail command.
CVE-1999-0128 5 Digital, Ibm, Linux and 2 more 9 Osf 1, Aix, Sng and 6 more 2008-09-09 5.0 MEDIUM N/A
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
CVE-1999-0134 1 Sun 1 Sunos 2008-09-09 7.2 HIGH N/A
vold in Solaris 2.x allows local users to gain root access.
CVE-1999-0016 6 Cisco, Gnu, Hp and 3 more 8 Ios, Inet, Hp-ux and 5 more 2008-09-09 5.0 MEDIUM N/A
Land IP denial of service.
CVE-1999-0142 2 Netscape, Sun 2 Navigator, Java 2008-09-09 7.5 HIGH N/A
The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.
CVE-1999-0186 1 Sun 1 Solaris 2008-09-09 10.0 HIGH N/A
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
CVE-1999-0169 1 Sun 1 Nfs 2008-09-09 10.0 HIGH N/A
NFS allows attackers to read and write any file on the system by specifying a false UID.
CVE-1999-0164 1 Sun 1 Sunos 2008-09-09 6.2 MEDIUM N/A
A race condition in the Solaris ps command allows an attacker to overwrite critical files.
CVE-1999-0166 1 Sun 1 Nfs 2008-09-09 5.0 MEDIUM N/A
NFS allows users to use a "cd .." command to access other directories besides the exported file system.
CVE-1999-0167 1 Sun 1 Sunos 2008-09-09 4.6 MEDIUM N/A
In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.
CVE-1999-0032 5 Bsdi, Freebsd, Next and 2 more 5 Bsd Os, Freebsd, Nextstep and 2 more 2008-09-09 7.2 HIGH N/A
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
CVE-1999-0033 5 Ibm, Ncr, Sco and 2 more 7 Aix, Mp-ras, Open Desktop and 4 more 2008-09-09 7.2 HIGH N/A
Command execution in Sun systems via buffer overflow in the at program.
CVE-1999-0019 7 Data General, Ibm, Ncr and 4 more 10 Dg Ux, Aix, Mp-ras and 7 more 2008-09-09 5.0 MEDIUM N/A
Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0017 9 Caldera, Freebsd, Gnu and 6 more 11 Openlinux, Freebsd, Inet and 8 more 2008-09-09 7.5 HIGH N/A
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
CVE-2007-3025 2 Clam Anti-virus, Sun 2 Clamav, Solaris 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service (hang) via unknown vectors related to the isURL function and regular expressions.
CVE-2005-4805 1 Sun 1 Java System Application Server 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update 2 and earlier, allows remote attackers to obtain the source code for Java Server pages (JSP) via unknown vectors.
CVE-2005-3238 1 Sun 1 Solaris 2008-09-05 2.1 LOW N/A
Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.
CVE-2005-2870 1 Sun 1 Solaris 2008-09-05 7.5 HIGH N/A
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
CVE-2005-1150 1 Sun 1 Java System Web Server 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).
CVE-2005-0576 1 Sun 1 Solaris 2008-09-05 3.6 LOW N/A
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
CVE-2005-0418 1 Sun 1 J2se 2008-09-05 7.5 HIGH N/A
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.
CVE-2003-1521 1 Sun 1 Java Plug-in 2008-09-05 6.4 MEDIUM N/A
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
CVE-2003-1516 1 Sun 1 Java Plug-in 2008-09-05 6.8 MEDIUM N/A
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.
CVE-2003-1134 1 Sun 1 Java 2008-09-05 2.1 LOW N/A
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.
CVE-2003-1125 1 Sun 1 One Directory Server 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).
CVE-2003-1126 1 Sun 1 One Web Server 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.
CVE-2003-0970 1 Sun 1 Sun Fire 2008-09-05 5.0 MEDIUM N/A
The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.
CVE-2002-2374 1 Sun 1 Patchpro 2008-09-05 10.0 HIGH N/A
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."
CVE-2002-2425 1 Sun 1 Solaris Answerbook2 2008-09-05 10.0 HIGH N/A
Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.
CVE-2002-2089 1 Sun 1 Solaris 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.
CVE-2002-2036 1 Sun 1 Ray Server Software 2008-09-05 7.5 HIGH N/A
Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.
CVE-2002-2072 1 Sun 1 Jre 2008-09-05 5.0 MEDIUM N/A
java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.
CVE-2002-2323 1 Sun 1 Solaris Pc Netlink 2008-09-05 5.0 MEDIUM N/A
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.
CVE-2002-1525 2 Astaware, Sun 2 Searchdisc, Sunone Starter Kit 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.
CVE-2002-0994 1 Sun 1 Sun Pci Ii Driver 2008-09-05 7.5 HIGH N/A
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.
CVE-2002-1034 1 Sun 1 I-runbook 2008-09-05 10.0 HIGH N/A
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.
CVE-2002-1042 2 Netscape, Sun 4 Enterprise Server, Iplanet Web Server, One Application Server and 1 more 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
CVE-2002-1033 1 Sun 1 I-runbook 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument.
CVE-2001-1306 1 Sun 1 Iplanet Directory Server 2008-09-05 7.5 HIGH N/A
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2001-1008 1 Sun 2 Java Plug-in, Jre 2008-09-05 7.5 HIGH N/A
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
CVE-2001-0632 1 Sun 1 Chilisoft 2008-09-05 7.5 HIGH N/A
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
CVE-2001-0633 1 Sun 1 Chilisoft 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.