Skip to main content

Vendor archive

sun CVEs

Beta · best-effort

1,581 CVEs tagged to vendor sun332 Critical, 382 High, 697 Medium, 168 Low, 2 Unrated.

CVE-2010-0453

Published Feb 3, 2010

The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4885

Published Jan 28, 2010

Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1575

Published Jan 28, 2010

VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circu…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0389

Published Jan 25, 2010

The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0388

Published Jan 25, 2010

Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0387

Published Jan 25, 2010

Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0386

Published Jan 25, 2010

The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authe…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0361

Published Jan 20, 2010

Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (da…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0360

Published Jan 20, 2010

Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malforme…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0313

Published Jan 14, 2010

The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer derefe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0310

Published Jan 14, 2010

Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0079

Published Jan 13, 2010

Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and avail…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0273

Published Jan 8, 2010

Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted dat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0272

Published Jan 8, 2010

Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as dem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0271

Published Jan 8, 2010

hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physicall…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4502

Published Dec 31, 2009

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4443

Published Dec 28, 2009

Unspecified vulnerability in the psearch (aka persistent search) functionality in Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4442

Published Dec 28, 2009

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4441

Published Dec 28, 2009

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not enable the SO_KEEPALIVE socket option, which makes it easier for rem…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4440

Published Dec 28, 2009

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time wind…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4314

Published Dec 14, 2009

Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which mak…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 576-600 of 1,581 CVEsPage 24 of 64