Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Total 1711 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0019 7 Data General, Ibm, Ncr and 4 more 10 Dg Ux, Aix, Mp-ras and 7 more 2025-04-03 5.0 MEDIUM N/A
Delete or create a file via rpc.statd, due to invalid information.
CVE-2005-4046 1 Sun 2 Java System Application Server, One Application Server 2025-04-03 4.0 MEDIUM N/A
Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers to conduct man-in-the-middle (MITM) attacks and "compromise data privacy."
CVE-2003-1521 1 Sun 1 Java Plug-in 2025-04-03 6.4 MEDIUM N/A
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
CVE-1999-1021 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
CVE-1999-0263 1 Sun 1 Sunos 2025-04-03 4.6 MEDIUM N/A
Solaris SUNWadmap can be exploited to obtain root access.
CVE-2001-0922 1 Sun 1 Netdynamics 2025-04-03 7.5 HIGH N/A
ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in.
CVE-2001-0470 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.
CVE-1999-0136 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
CVE-2004-1815 2 Macromedia, Sun 3 Coldfusion, Jrun, One Application Server 2025-04-03 5.0 MEDIUM N/A
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).
CVE-2002-1199 3 Caldera, Sco, Sun 4 Openlinux, Openserver, Solaris and 1 more 2025-04-03 5.0 MEDIUM N/A
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
CVE-2005-2870 1 Sun 1 Solaris 2025-04-03 7.5 HIGH N/A
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
CVE-2001-0190 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
CVE-1999-1211 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.
CVE-1999-0966 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].
CVE-2000-0117 1 Sun 3 Cobalt Raq, Cobalt Raq 2, Cobalt Raq 3i 2025-04-03 7.2 HIGH N/A
The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).
CVE-1999-0120 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.
CVE-2000-0812 1 Sun 1 Java System Web Server 2025-04-03 10.0 HIGH N/A
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.
CVE-1999-1527 1 Sun 2 Forte, Netbeans Developer 2025-04-03 7.5 HIGH N/A
Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.
CVE-1999-0676 1 Sun 2 Solaris, Sunos 2025-04-03 4.6 MEDIUM N/A
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVE-1999-0186 1 Sun 1 Solaris 2025-04-03 10.0 HIGH N/A
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.