Skip to main content

Vendor/product archive

sun / java_system_web_server CVEs

Beta · best-effort

32 CVEs tagged to sun / java_system_web_server5 Critical, 7 High, 19 Medium, 1 Low, 0 Unrated.

CVE-2010-0389

Published Jan 25, 2010

The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0388

Published Jan 25, 2010

Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0387

Published Jan 25, 2010

Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0361

Published Jan 20, 2010

Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (da…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0360

Published Jan 20, 2010

Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malforme…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0273

Published Jan 8, 2010

Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted dat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0272

Published Jan 8, 2010

Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as dem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2445

Published Jul 13, 2009

Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2518

Published Jun 3, 2008

Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2166

Published May 13, 2008

Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4164

Published Aug 7, 2007

CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1526

Published Mar 20, 2007

Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization con…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1488

Published Mar 16, 2007

Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample appl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2