Vendor CVEs
Sun Corporation
All CVEs
1,847 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-1066 | 0.00 | — | 0.00 | Aug 31, 2001 | ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2001-1008 | 0.00 | — | 0.02 | Aug 31, 2001 | Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate. | |||
| CVE-2001-0634 | 0.00 | — | 0.00 | Aug 22, 2001 | Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service. | |||
| CVE-2001-0606 | 0.00 | — | 0.02 | Aug 22, 2001 | Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service. | |||
| CVE-2001-0632 | 0.00 | — | 0.02 | Aug 22, 2001 | Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges. | |||
| CVE-2001-0633 | 0.00 | — | 0.02 | Aug 22, 2001 | Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'. | |||
| CVE-2001-0353 | 0.00 | — | 0.04 | Jul 21, 2001 | Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine. | |||
| CVE-2001-1308 | 0.00 | — | 0.05 | Jul 16, 2001 | Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | |||
| CVE-2001-1307 | 0.00 | — | 0.05 | Jul 16, 2001 | Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | |||
| CVE-2001-1306 | 0.00 | — | 0.04 | Jul 16, 2001 | iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite. | |||
| CVE-2001-1244 | 0.00 | — | 0.21 | Jul 7, 2001 | Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that… | |||
| CVE-2001-0470 | 0.00 | — | 0.00 | Jun 27, 2001 | Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name. | |||
| CVE-2001-0404 | 0.00 | — | 0.02 | Jun 18, 2001 | Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory. | |||
| CVE-2001-0269 | 0.00 | — | 0.03 | May 3, 2001 | pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password. | |||
| CVE-2001-0229 | 0.00 | — | 0.00 | May 3, 2001 | Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts. | |||
| CVE-2001-0190 | 0.00 | — | 0.00 | Mar 26, 2001 | Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0). | |||
| CVE-2001-0124 | 0.00 | — | 0.00 | Mar 12, 2001 | Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument. | |||
| CVE-2001-0078 | 0.00 | — | 0.00 | Feb 12, 2001 | in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS. | |||
| CVE-2001-0077 | 0.00 | — | 0.01 | Feb 12, 2001 | The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations. | |||
| CVE-2000-1099 | 0.00 | — | 0.02 | Jan 9, 2001 | Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities. | |||
| CVE-2000-1156 | 0.00 | — | 0.00 | Jan 9, 2001 | StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice. | |||
| CVE-2000-1076 | 0.00 | — | 0.02 | Dec 11, 2000 | Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server. | |||
| CVE-2000-0812 | 0.00 | — | 0.06 | Nov 14, 2000 | The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag. | |||
| CVE-2000-0629 | 0.00 | — | 0.04 | Jul 12, 2000 | The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet. | |||
| CVE-2000-0431 | 0.00 | — | 0.01 | May 22, 2000 | Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files. | |||
| CVE-2000-0320 | 0.00 | — | 0.01 | Apr 21, 2000 | Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n. | |||
| CVE-2000-0291 | 0.00 | — | 0.00 | Apr 16, 2000 | Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document. | |||
| CVE-2000-0175 | 0.00 | — | 0.02 | Mar 9, 2000 | Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command. | |||
| CVE-2000-0164 | 0.00 | — | 0.01 | Feb 20, 2000 | The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords. | |||
| CVE-2000-0117 | 0.00 | — | 0.00 | Jan 30, 2000 | The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root). | |||
| CVE-2000-0055 | 0.00 | — | 0.00 | Jan 6, 2000 | Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option. | |||
| CVE-2000-0069 | 0.00 | — | 0.00 | Jan 1, 2000 | The recover program in Solstice Backup allows local users to restore sensitive files. | |||
| CVE-1999-1585 | 0.00 | — | 0.00 | Dec 31, 1999 | The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges. | |||
| CVE-1999-1102 | 0.00 | — | 0.00 | Dec 31, 1999 | lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times. | |||
| CVE-1999-1584 | 0.00 | — | 0.01 | Dec 31, 1999 | Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586. | |||
| CVE-1999-1592 | 0.00 | — | 0.01 | Dec 31, 1999 | Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129. | |||
| CVE-1999-1586 | 0.00 | — | 0.00 | Dec 31, 1999 | loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584. | |||
| CVE-2000-0030 | 0.00 | — | 0.01 | Dec 22, 1999 | Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database. | |||
| CVE-1999-0974 | 0.00 | — | 0.03 | Dec 9, 1999 | Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service. | |||
| CVE-1999-0982 | 0.00 | — | 0.00 | Dec 5, 1999 | The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file. | |||
| CVE-1999-0840 | 0.00 | — | 0.00 | Nov 30, 1999 | Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option. | |||
| CVE-1999-1527 | 0.00 | — | 0.02 | Nov 23, 1999 | Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server. | |||
| CVE-1999-0831 | 0.00 | — | 0.01 | Nov 19, 1999 | Denial of service in Linux syslogd via a large number of connections. | |||
| CVE-1999-0851 | 0.00 | — | 0.00 | Nov 10, 1999 | Denial of service in BIND named via naptr. | |||
| CVE-1999-0837 | 0.00 | — | 0.03 | Nov 10, 1999 | Denial of service in BIND by improperly closing TCP sessions via so_linger. | |||
| CVE-1999-0835 | 0.00 | — | 0.01 | Nov 10, 1999 | Denial of service in BIND named via malformed SIG records. | |||
| CVE-1999-0833 | 0.00 | — | 0.02 | Nov 10, 1999 | Buffer overflow in BIND 8.2 via NXT records. | |||
| CVE-1999-1530 | 0.00 | — | 0.00 | Nov 8, 1999 | cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system. | |||
| CVE-1999-0687 | 0.00 | — | 0.02 | Sep 13, 1999 | The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. | |||
| CVE-1999-0676 | 0.00 | — | 0.00 | Aug 9, 1999 | sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack. |
- CVE-2001-1066Aug 31, 2001risk 0.00cvss —epss 0.00
ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2001-1008Aug 31, 2001risk 0.00cvss —epss 0.02
Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.
- CVE-2001-0634Aug 22, 2001risk 0.00cvss —epss 0.00
Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service.
- CVE-2001-0606Aug 22, 2001risk 0.00cvss —epss 0.02
Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.
- CVE-2001-0632Aug 22, 2001risk 0.00cvss —epss 0.02
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
- CVE-2001-0633Aug 22, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.
- CVE-2001-0353Jul 21, 2001risk 0.00cvss —epss 0.04
Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.
- CVE-2001-1308Jul 16, 2001risk 0.00cvss —epss 0.05
Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
- CVE-2001-1307Jul 16, 2001risk 0.00cvss —epss 0.05
Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
- CVE-2001-1306Jul 16, 2001risk 0.00cvss —epss 0.04
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
- CVE-2001-1244Jul 7, 2001risk 0.00cvss —epss 0.21
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that…
- CVE-2001-0470Jun 27, 2001risk 0.00cvss —epss 0.00
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
- CVE-2001-0404Jun 18, 2001risk 0.00cvss —epss 0.02
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.
- CVE-2001-0269May 3, 2001risk 0.00cvss —epss 0.03
pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
- CVE-2001-0229May 3, 2001risk 0.00cvss —epss 0.00
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.
- CVE-2001-0190Mar 26, 2001risk 0.00cvss —epss 0.00
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
- CVE-2001-0124Mar 12, 2001risk 0.00cvss —epss 0.00
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
- CVE-2001-0078Feb 12, 2001risk 0.00cvss —epss 0.00
in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.
- CVE-2001-0077Feb 12, 2001risk 0.00cvss —epss 0.01
The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.
- CVE-2000-1099Jan 9, 2001risk 0.00cvss —epss 0.02
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.
- CVE-2000-1156Jan 9, 2001risk 0.00cvss —epss 0.00
StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.
- CVE-2000-1076Dec 11, 2000risk 0.00cvss —epss 0.02
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.
- CVE-2000-0812Nov 14, 2000risk 0.00cvss —epss 0.06
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
- CVE-2000-0629Jul 12, 2000risk 0.00cvss —epss 0.04
The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.
- CVE-2000-0431May 22, 2000risk 0.00cvss —epss 0.01
Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.
- CVE-2000-0320Apr 21, 2000risk 0.00cvss —epss 0.01
Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.
- CVE-2000-0291Apr 16, 2000risk 0.00cvss —epss 0.00
Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.
- CVE-2000-0175Mar 9, 2000risk 0.00cvss —epss 0.02
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
- CVE-2000-0164Feb 20, 2000risk 0.00cvss —epss 0.01
The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.
- CVE-2000-0117Jan 30, 2000risk 0.00cvss —epss 0.00
The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).
- CVE-2000-0055Jan 6, 2000risk 0.00cvss —epss 0.00
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.
- CVE-2000-0069Jan 1, 2000risk 0.00cvss —epss 0.00
The recover program in Solstice Backup allows local users to restore sensitive files.
- CVE-1999-1585Dec 31, 1999risk 0.00cvss —epss 0.00
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.
- CVE-1999-1102Dec 31, 1999risk 0.00cvss —epss 0.00
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
- CVE-1999-1584Dec 31, 1999risk 0.00cvss —epss 0.01
Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.
- CVE-1999-1592Dec 31, 1999risk 0.00cvss —epss 0.01
Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.
- CVE-1999-1586Dec 31, 1999risk 0.00cvss —epss 0.00
loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.
- CVE-2000-0030Dec 22, 1999risk 0.00cvss —epss 0.01
Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.
- CVE-1999-0974Dec 9, 1999risk 0.00cvss —epss 0.03
Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.
- CVE-1999-0982Dec 5, 1999risk 0.00cvss —epss 0.00
The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.
- CVE-1999-0840Nov 30, 1999risk 0.00cvss —epss 0.00
Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.
- CVE-1999-1527Nov 23, 1999risk 0.00cvss —epss 0.02
Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.
- CVE-1999-0831Nov 19, 1999risk 0.00cvss —epss 0.01
Denial of service in Linux syslogd via a large number of connections.
- CVE-1999-0851Nov 10, 1999risk 0.00cvss —epss 0.00
Denial of service in BIND named via naptr.
- CVE-1999-0837Nov 10, 1999risk 0.00cvss —epss 0.03
Denial of service in BIND by improperly closing TCP sessions via so_linger.
- CVE-1999-0835Nov 10, 1999risk 0.00cvss —epss 0.01
Denial of service in BIND named via malformed SIG records.
- CVE-1999-0833Nov 10, 1999risk 0.00cvss —epss 0.02
Buffer overflow in BIND 8.2 via NXT records.
- CVE-1999-1530Nov 8, 1999risk 0.00cvss —epss 0.00
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.
- CVE-1999-0687Sep 13, 1999risk 0.00cvss —epss 0.02
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
- CVE-1999-0676Aug 9, 1999risk 0.00cvss —epss 0.00
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Page 35 of 37