Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Total 1704 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0722 1 Sun 1 Cobalt Raq 2 2025-04-03 10.0 HIGH N/A
The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
CVE-2006-1782 1 Sun 2 Solaris, Sunos 2025-04-03 2.1 LOW N/A
Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.
CVE-1999-0860 1 Sun 2 Solaris, Sunos 2025-04-03 2.1 LOW N/A
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
CVE-1999-0015 4 Hp, Microsoft, Netbsd and 1 more 5 Hp-ux, Windows 95, Windows Nt and 2 more 2025-04-03 5.0 MEDIUM N/A
Teardrop IP denial of service.
CVE-2001-0124 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
CVE-2006-4307 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.
CVE-1999-0369 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
CVE-2002-2036 1 Sun 1 Ray Server Software 2025-04-03 7.5 HIGH N/A
Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.
CVE-2005-0576 1 Sun 1 Solaris 2025-04-03 3.6 LOW N/A
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
CVE-2006-3921 1 Sun 2 Java System Application Server, Java System Web Server 2025-04-03 4.0 MEDIUM N/A
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.
CVE-2005-1150 1 Sun 1 Java System Web Server 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).
CVE-2005-4046 1 Sun 2 Java System Application Server, One Application Server 2025-04-03 4.0 MEDIUM N/A
Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers to conduct man-in-the-middle (MITM) attacks and "compromise data privacy."
CVE-1999-0696 2 Hp, Sun 3 Hp-ux, Solaris, Sunos 2025-04-03 10.0 HIGH N/A
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
CVE-2002-0391 4 Freebsd, Microsoft, Openbsd and 1 more 7 Freebsd, Windows 2000, Windows Nt and 4 more 2025-04-03 10.0 HIGH 9.8 CRITICAL
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
CVE-2006-2501 1 Sun 4 Java System Application Server, Java System Web Server, One Application Server and 1 more 2025-04-03 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving error messages.
CVE-2002-0084 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.
CVE-2005-3583 1 Sun 2 Jre, Sdk 2025-04-03 7.8 HIGH N/A
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss.
CVE-1999-0689 2 Cde, Sun 3 Cde, Solaris, Sunos 2025-04-03 7.2 HIGH N/A
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
CVE-1999-1432 1 Sun 2 Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.
CVE-2005-2094 1 Sun 1 One Web Server 2025-04-03 4.3 MEDIUM N/A
Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."