VYPR

Vendor CVEs

Sun Corporation

All CVEs

1,847 total · sorted by risk
  • CVE-2006-0227Jan 17, 2006
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.

  • CVE-2006-0191Jan 13, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this…

  • CVE-2006-0190Jan 13, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.

  • CVE-2006-0161Jan 10, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.

  • CVE-2005-1753Dec 31, 2005
    risk 0.00cvss epss 0.01

    ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes…

  • CVE-2005-4795Dec 31, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.

  • CVE-2005-4796Dec 31, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.

  • CVE-2005-2530Dec 31, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to "Mac OS X specific extensions."

  • CVE-2005-4845Dec 31, 2005
    risk 0.00cvss epss 0.02

    The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not…

  • CVE-2005-4805Dec 31, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update 2 and earlier, allows remote attackers to obtain the source code for Java Server pages (JSP) via unknown vectors.

  • CVE-2005-4701Dec 31, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Process File System (procfs) in Sun Solaris 10 allows local users to obtain sensitive information such as process working directories via unknown attack vectors, possibly pwdx.

  • CVE-2005-4706Dec 31, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the "privilege management" feature of Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors that trigger a null dereference in the secpolicy_fs_common function.

  • CVE-2005-2529Dec 31, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives."

  • CVE-2005-2527Dec 31, 2005
    risk 0.00cvss epss 0.00

    Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack.

  • CVE-2005-2738Dec 31, 2005
    risk 0.00cvss epss 0.02

    Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program.

  • CVE-2005-3658Dec 31, 2005
    risk 0.00cvss epss 0.05

    Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute…

  • CVE-2005-3659Dec 31, 2005
    risk 0.00cvss epss 0.03

    nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd…

  • CVE-2005-4804Dec 31, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications.

  • CVE-2005-4806Dec 31, 2005
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.

  • CVE-2005-4552Dec 28, 2005
    risk 0.00cvss epss 0.00

    The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.

  • CVE-2005-4350Dec 20, 2005
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 and A.02.x before A.02.00.08 on HP-UX B.11.00 through B.11.23 allows remote attackers to cause an unspecified denial of service via unknown attack vectors.

  • CVE-2005-4133Dec 9, 2005
    risk 0.00cvss epss 0.00

    Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files.

  • CVE-2005-4046Dec 7, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers…

  • CVE-2005-4045Dec 7, 2005
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving…

  • CVE-2005-3904Nov 30, 2005
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.

  • CVE-2005-3907Nov 30, 2005
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.

  • CVE-2005-3906Nov 30, 2005
    risk 0.00cvss epss 0.05

    Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors, a…

  • CVE-2005-3905Nov 30, 2005
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack…

  • CVE-2005-3781Nov 23, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in in.named in Solaris 9 allows attackers to cause a denial of service via unknown manipulations that cause in.named to "make unnecessary queries."

  • CVE-2005-3674Nov 18, 2005
    risk 0.00cvss epss 0.05

    The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked crash) via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to…

  • CVE-2005-3583Nov 16, 2005
    risk 0.00cvss epss 0.03

    (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on…

  • CVE-2005-3472Nov 3, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.

  • CVE-2005-3269Oct 20, 2005
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5)…

  • CVE-2005-3250Oct 17, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors related to the "/proc" filesystem, which trigger a null dereference.

  • CVE-2005-3238Oct 14, 2005
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.

  • CVE-2005-3099Sep 28, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.

  • CVE-2005-3071Sep 27, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.

  • CVE-2005-3001Sep 20, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

  • CVE-2005-2870Sep 8, 2005
    risk 0.00cvss epss 0.03

    Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.

  • CVE-2005-0359Aug 23, 2005
    risk 0.00cvss epss 0.04

    The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to…

  • CVE-2005-0358Aug 23, 2005
    risk 0.00cvss epss 0.05

    EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.

  • CVE-2005-0357Aug 23, 2005
    risk 0.00cvss epss 0.04

    EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or…

  • CVE-2005-2094Jul 5, 2005
    risk 0.00cvss epss 0.01

    Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly…

  • CVE-2005-2022Jun 17, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.

  • CVE-2005-1973Jun 16, 2005
    risk 0.00cvss epss 0.02

    Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.

  • CVE-2005-2032Jun 16, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.

  • CVE-2005-1974Jun 16, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain…

  • CVE-2005-1887Jun 9, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.

  • CVE-2005-1889Jun 7, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.

  • CVE-2005-1682May 20, 2005
    risk 0.00cvss epss 0.01

    JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users' e-mail messages by modifying the…

Page 31 of 37