Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Total 1712 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-3723 1 Sun 1 Solaris 2008-11-15 2.1 LOW N/A
The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and performs scheduling based upon CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."
CVE-2007-2904 1 Sun 1 Java System Messaging Server 2008-11-15 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.
CVE-2007-0183 1 Sun 1 Iplanet Web Server 2008-11-15 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-2906 1 Sun 1 Java Embedding Plugin 2008-11-13 5.0 MEDIUM N/A
Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method.
CVE-2000-0697 1 Sun 1 Solaris Answerbook2 2008-09-24 10.0 HIGH N/A
The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.
CVE-2002-0430 1 Sun 3 Cobalt Raq 2, Cobalt Raq 3i, Cobalt Raq 4 2008-09-10 3.7 LOW N/A
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.
CVE-2000-0629 1 Sun 1 Java System Web Server 2008-09-10 7.5 HIGH N/A
The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.
CVE-2000-0442 2 Qualcomm, Sun 3 Qpopper, Cobalt Raq 2, Cobalt Raq 3i 2008-09-10 7.5 HIGH N/A
Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
CVE-2000-0291 1 Sun 1 Staroffice 2008-09-10 4.6 MEDIUM N/A
Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.
CVE-2000-0210 1 Sun 1 Workshop 2008-09-10 1.2 LOW N/A
The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.
CVE-2000-0175 1 Sun 1 Staroffice 2008-09-10 10.0 HIGH N/A
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
CVE-2000-0174 1 Sun 1 Staroffice 2008-09-10 5.0 MEDIUM N/A
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-2000-0117 1 Sun 3 Cobalt Raq, Cobalt Raq 2, Cobalt Raq 3i 2008-09-10 7.2 HIGH N/A
The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).
CVE-1999-1468 4 Cray, Next, Sgi and 1 more 4 Unicos, Next, Irix and 1 more 2008-09-10 6.2 MEDIUM N/A
rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.
CVE-2008-3440 1 Sun 1 Java 2008-09-10 7.5 HIGH N/A
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
CVE-1999-0831 4 Cobalt, Debian, Sun and 1 more 6 Qube, Debian Linux, Cobalt Raq and 3 more 2008-09-09 5.0 MEDIUM N/A
Denial of service in Linux syslogd via a large number of connections.
CVE-1999-0797 1 Sun 1 Sunos 2008-09-09 2.6 LOW N/A
NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.
CVE-1999-0722 1 Sun 1 Cobalt Raq 2 2008-09-09 10.0 HIGH N/A
The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
CVE-1999-0408 1 Sun 1 Cobalt Raq 2008-09-09 10.0 HIGH N/A
Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.
CVE-1999-0298 2 Slackware, Sun 2 Slackware Linux, Sunos 2008-09-09 7.5 HIGH N/A
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.