Filtered by vendor Sun
Subscribe
Total
1705 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2004-0817 | 9 Conectiva, Enlightenment, Imagemagick and 6 more | 16 Linux, Imlib, Imlib2 and 13 more | 2017-10-10 | 7.5 HIGH | N/A |
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file. | |||||
CVE-2004-1358 | 1 Sun | 1 Solaris | 2017-10-10 | 5.0 MEDIUM | N/A |
The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged. | |||||
CVE-2002-0090 | 1 Sun | 1 Solaris | 2017-10-09 | 7.2 HIGH | N/A |
Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option. | |||||
CVE-2002-0387 | 1 Sun | 1 One Application Server | 2017-10-09 | 7.5 HIGH | N/A |
Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL. | |||||
CVE-2001-1328 | 1 Sun | 1 Sunos | 2017-10-09 | 7.5 HIGH | N/A |
Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code. | |||||
CVE-2002-1361 | 1 Sun | 1 Cobalt Raq 4 | 2017-10-09 | 10.0 HIGH | N/A |
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter. | |||||
CVE-1999-1021 | 1 Sun | 1 Sunos | 2017-10-09 | 7.2 HIGH | N/A |
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade. | |||||
CVE-1999-1258 | 1 Sun | 1 Sunos | 2017-10-09 | 5.0 MEDIUM | N/A |
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information. | |||||
CVE-2000-0958 | 1 Sun | 1 Hotjava Browser | 2017-10-09 | 5.0 MEDIUM | N/A |
HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window. | |||||
CVE-2000-1075 | 2 Netscape, Sun | 2 Directory Server, Iplanet Certificate Management System | 2017-10-09 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services. | |||||
CVE-2001-0078 | 1 Sun | 1 Cluster | 2017-10-09 | 2.1 LOW | N/A |
in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS. | |||||
CVE-2001-0423 | 1 Sun | 1 Solaris | 2017-10-09 | 7.2 HIGH | N/A |
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093. | |||||
CVE-1999-1507 | 1 Sun | 1 Sunos | 2017-10-09 | 7.2 HIGH | N/A |
Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash. | |||||
CVE-1999-1142 | 1 Sun | 1 Sunos | 2017-10-09 | 7.2 HIGH | N/A |
SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user. | |||||
CVE-2001-0634 | 1 Sun | 1 Chilisoft | 2017-10-09 | 7.2 HIGH | N/A |
Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service. | |||||
CVE-2001-1075 | 1 Sun | 1 Cobalt Raq 3i | 2017-10-09 | 5.0 MEDIUM | N/A |
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file. | |||||
CVE-1999-1118 | 1 Sun | 1 Solaris | 2017-10-09 | 2.1 LOW | N/A |
ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters. | |||||
CVE-2001-0077 | 1 Sun | 1 Cluster | 2017-10-09 | 5.0 MEDIUM | N/A |
The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations. | |||||
CVE-1999-0084 | 1 Sun | 1 Nfs | 2017-10-09 | 7.2 HIGH | N/A |
Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0. | |||||
CVE-2009-2135 | 1 Sun | 2 Opensolaris, Solaris | 2017-09-28 | 4.9 MEDIUM | N/A |
Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions. |