sun CVE Vulnerabilities & Metrics

Focus on sun vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About sun Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sun. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sun CVEs: 36
Earliest CVE date: 26 Jul 1989, 04:00 UTC
Latest CVE date: 01 Dec 2021, 02:15 UTC

Latest CVE reference: CVE-2021-43360

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sun CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.29

Max CVSS: 10.0

Critical CVEs (≥9): 288

CVSS Range vs. Count

Range Count
0.0-3.9 173
4.0-6.9 700
7.0-8.9 428
9.0-10.0 288

CVSS Distribution Chart

Top 5 Highest CVSS sun CVEs

These are the five CVEs with the highest CVSS scores for sun, sorted by severity first and recency.

All CVEs for sun

CVE-2021-43360 sun vulnerability CVSS: 9.0 01 Dec 2021, 02:15 UTC

Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and control the system or interrupt services.

CVE-2021-43359 sun vulnerability CVSS: 9.0 01 Dec 2021, 02:15 UTC

Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.

CVE-2021-43358 sun vulnerability CVSS: 7.8 01 Dec 2021, 02:15 UTC

Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.

CVE-2020-10510 sun vulnerability CVSS: 4.0 27 Mar 2020, 08:15 UTC

Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

CVE-2020-10509 sun vulnerability CVSS: 4.3 27 Mar 2020, 08:15 UTC

Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), attackers can inject arbitrary command into the system and launch XSS attack.

CVE-2020-10508 sun vulnerability CVSS: 5.0 27 Mar 2020, 08:15 UTC

Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a specific URL and capture confidential information.

CVE-2016-1291 sun vulnerability CVSS: 9.3 06 Apr 2016, 23:59 UTC

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

CVE-2016-1290 sun vulnerability CVSS: 5.5 06 Apr 2016, 23:59 UTC

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.

CVE-2015-6313 sun vulnerability CVSS: 7.8 06 Apr 2016, 23:59 UTC

Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv47565.

CVE-2016-1314 sun vulnerability CVSS: 3.5 28 Mar 2016, 23:59 UTC

Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux80760.

CVE-2016-1350 sun vulnerability CVSS: 7.8 26 Mar 2016, 01:59 UTC

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

CVE-2016-1349 sun vulnerability CVSS: 7.8 26 Mar 2016, 01:59 UTC

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

CVE-2016-1348 sun vulnerability CVSS: 7.8 26 Mar 2016, 01:59 UTC

Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.

CVE-2016-1344 sun vulnerability CVSS: 7.1 26 Mar 2016, 01:59 UTC

The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.

CVE-2015-0718 sun vulnerability CVSS: 7.8 03 Mar 2016, 22:59 UTC

Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.

CVE-2016-1329 sun vulnerability CVSS: 10.0 03 Mar 2016, 11:59 UTC

Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.

CVE-2016-1331 sun vulnerability CVSS: 4.3 15 Feb 2016, 23:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.

CVE-2016-1319 sun vulnerability CVSS: 5.0 09 Feb 2016, 03:59 UTC

Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.

CVE-2016-1302 sun vulnerability CVSS: 9.0 07 Feb 2016, 11:59 UTC

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.

CVE-2016-1310 sun vulnerability CVSS: 4.3 06 Feb 2016, 05:59 UTC

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.

CVE-2016-1306 sun vulnerability CVSS: 4.3 06 Feb 2016, 05:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466.

CVE-2015-6319 sun vulnerability CVSS: 10.0 27 Jan 2016, 22:59 UTC

SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.

CVE-2015-0430 sun vulnerability CVSS: 1.9 21 Jan 2015, 19:59 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality via vectors related to RPC Utility.

CVE-2015-0429 sun vulnerability CVSS: 3.3 21 Jan 2015, 19:59 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to RPC Utility.

CVE-2015-0428 sun vulnerability CVSS: 4.9 21 Jan 2015, 19:59 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Resource Control.

CVE-2015-0397 sun vulnerability CVSS: 2.1 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6570 and CVE-2014-6600.

CVE-2015-0375 sun vulnerability CVSS: 5.0 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect confidentiality via unknown vectors related to Network.

CVE-2014-6600 sun vulnerability CVSS: 4.9 21 Jan 2015, 18:59 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6570 and CVE-2015-0397.

CVE-2014-6575 sun vulnerability CVSS: 5.0 21 Jan 2015, 15:28 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE-2004-0230.

CVE-2014-6570 sun vulnerability CVSS: 4.9 21 Jan 2015, 15:28 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6600 and CVE-2015-0397.

CVE-2014-6524 sun vulnerability CVSS: 7.2 21 Jan 2015, 14:59 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

CVE-2014-6521 sun vulnerability CVSS: 7.2 21 Jan 2015, 14:59 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via vectors related to CDE - Power Management Utility.

CVE-2014-6518 sun vulnerability CVSS: 6.6 21 Jan 2015, 14:59 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS).

CVE-2014-6510 sun vulnerability CVSS: 7.2 21 Jan 2015, 14:59 UTC

Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility.

CVE-2014-6509 sun vulnerability CVSS: 4.9 21 Jan 2015, 14:59 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.

CVE-2014-6481 sun vulnerability CVSS: 4.3 21 Jan 2015, 14:59 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidentiality via vectors related to KSSL.

CVE-2014-6529 sun vulnerability CVSS: 6.8 15 Oct 2014, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hermon HCA PCIe driver.

CVE-2014-6508 sun vulnerability CVSS: 7.8 15 Oct 2014, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to iSCSI Data Mover (IDM).

CVE-2014-6501 sun vulnerability CVSS: 2.1 15 Oct 2014, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via vectors related to SSH.

CVE-2014-6497 sun vulnerability CVSS: 4.9 15 Oct 2014, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Kernel.

CVE-2014-6490 sun vulnerability CVSS: 5.0 15 Oct 2014, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB server user component.

CVE-2014-6473 sun vulnerability CVSS: 7.2 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Framework.

CVE-2014-6470 sun vulnerability CVSS: 6.8 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Archive Utility.

CVE-2014-4284 sun vulnerability CVSS: 4.4 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.

CVE-2014-4283 sun vulnerability CVSS: 4.3 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality via unknown vectors related to Automated Install Engine, a different vulnerability than CVE-2014-4277.

CVE-2014-4282 sun vulnerability CVSS: 7.2 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel/X86.

CVE-2014-4280 sun vulnerability CVSS: 4.6 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4284.

CVE-2014-4277 sun vulnerability CVSS: 5.0 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality via unknown vectors related to Automated Install Engine, a different vulnerability than CVE-2014-4283.

CVE-2014-4276 sun vulnerability CVSS: 7.5 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Common Internet File System (CIFS).

CVE-2014-4275 sun vulnerability CVSS: 4.9 15 Oct 2014, 15:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via vectors related to SMB server kernel module.

CVE-2014-4239 sun vulnerability CVSS: 4.0 17 Jul 2014, 11:17 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Common Agent Container (Cacao).

CVE-2014-4225 sun vulnerability CVSS: 6.9 17 Jul 2014, 05:10 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Patch installation scripts.

CVE-2014-4224 sun vulnerability CVSS: 4.9 17 Jul 2014, 05:10 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows local users to affect availability via unknown vectors related to sockfs.

CVE-2014-4215 sun vulnerability CVSS: 4.9 17 Jul 2014, 05:10 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to CPU performance counters (CPC) drivers, a different vulnerability than CVE-2013-5862.

CVE-2014-0447 sun vulnerability CVSS: 4.9 16 Apr 2014, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2013-5876.

CVE-2014-0442 sun vulnerability CVSS: 4.6 16 Apr 2014, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Print Filter Utility.

CVE-2014-0421 sun vulnerability CVSS: 4.6 16 Apr 2014, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10, when running on the SPARC64-X Platform, allows local users to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2013-5883 sun vulnerability CVSS: 3.2 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Solaris 8 allows local users to affect integrity and availability via unknown vectors related to Kernel.

CVE-2013-5876 sun vulnerability CVSS: 4.9 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2014-0447.

CVE-2013-5872 sun vulnerability CVSS: 2.1 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to Name Service Cache Daemon (NSCD).

CVE-2013-5834 sun vulnerability CVSS: 6.2 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Solaris 8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ps.

CVE-2013-5833 sun vulnerability CVSS: 4.9 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Solaris 8 and 9 allows local users to affect availability via unknown vectors related to Filesystem.

CVE-2013-5821 sun vulnerability CVSS: 4.6 15 Jan 2014, 16:11 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via vectors related to RPC.

CVE-2014-0390 sun vulnerability CVSS: 4.3 15 Jan 2014, 16:08 UTC

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Java Web Console.

CVE-2013-5864 sun vulnerability CVSS: 4.9 16 Oct 2013, 18:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to USB hub driver.

CVE-2013-5862 sun vulnerability CVSS: 4.9 16 Oct 2013, 18:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to CPU performance counters (CPC) drivers, a different vulnerability than CVE-2014-4215.

CVE-2013-5852 sun vulnerability CVSS: 7.6 16 Oct 2013, 18:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5832.

CVE-2013-5850 sun vulnerability CVSS: 9.3 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5842.

CVE-2013-5849 sun vulnerability CVSS: 4.3 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to AWT.

CVE-2013-5840 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

CVE-2013-5839 sun vulnerability CVSS: 4.3 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Oracle Java Web Console.

CVE-2013-5832 sun vulnerability CVSS: 9.3 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5852.

CVE-2013-5831 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5818 and CVE-2013-5819.

CVE-2013-5825 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JAXP.

CVE-2013-5824 sun vulnerability CVSS: 10.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5832, and CVE-2013-5852.

CVE-2013-5823 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

CVE-2013-5820 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to JAX-WS.

CVE-2013-5819 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5818 and CVE-2013-5831.

CVE-2013-5818 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5819 and CVE-2013-5831.

CVE-2013-5817 sun vulnerability CVSS: 10.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI.

CVE-2013-5814 sun vulnerability CVSS: 10.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.

CVE-2013-5812 sun vulnerability CVSS: 6.4 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.

CVE-2013-5809 sun vulnerability CVSS: 10.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-5829.

CVE-2013-5804 sun vulnerability CVSS: 6.4 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc.

CVE-2013-5803 sun vulnerability CVSS: 2.6 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.

CVE-2013-5802 sun vulnerability CVSS: 7.5 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP.

CVE-2013-5801 sun vulnerability CVSS: 5.0 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.

CVE-2013-5797 sun vulnerability CVSS: 3.5 16 Oct 2013, 17:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.

CVE-2013-5790 sun vulnerability CVSS: 4.3 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to BEANS.

CVE-2013-5789 sun vulnerability CVSS: 10.0 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.

CVE-2013-5787 sun vulnerability CVSS: 10.0 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5789, CVE-2013-5824, CVE-2013-5832, and CVE-2013-5852.

CVE-2013-5784 sun vulnerability CVSS: 4.3 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to SCRIPTING.

CVE-2013-5783 sun vulnerability CVSS: 6.4 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Swing.

CVE-2013-5782 sun vulnerability CVSS: 10.0 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2013-5780 sun vulnerability CVSS: 4.3 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

CVE-2013-5778 sun vulnerability CVSS: 5.0 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, 6u60 and earlier, 5.0u51 and earlier, and Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.

CVE-2013-5776 sun vulnerability CVSS: 5.0 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVE-2013-5774 sun vulnerability CVSS: 5.0 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, 6u60 and earlier, 5.0u51 and earlier, and Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to Libraries.

CVE-2013-5772 sun vulnerability CVSS: 2.6 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Java SE 6u60 and earlier allows remote attackers to affect integrity via unknown vectors related to jhat.

CVE-2013-3842 sun vulnerability CVSS: 2.1 16 Oct 2013, 15:55 UTC

Unspecified vulnerability Oracle Solaris 10 allows local users to affect confidentiality via vectors related to Oracle Configuration Manager (OCM).

CVE-2013-3837 sun vulnerability CVSS: 4.3 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows remote attackers to affect availability via unknown vectors related to Cacao.

CVE-2013-3829 sun vulnerability CVSS: 6.4 16 Oct 2013, 15:55 UTC

Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.

CVE-2013-3813 sun vulnerability CVSS: 5.8 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality and integrity via vectors related to Libraries/PAM-Unix.

CVE-2013-3799 sun vulnerability CVSS: 4.9 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11, when running on AMD64, allows local users to affect availability via unknown vectors related to Kernel.

CVE-2013-3797 sun vulnerability CVSS: 4.7 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 11 allows local users to affect availability via unknown vectors related to Filesystem/DevFS.

CVE-2013-3787 sun vulnerability CVSS: 4.3 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Kernel.

CVE-2013-3786 sun vulnerability CVSS: 6.0 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

CVE-2013-3765 sun vulnerability CVSS: 4.9 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 11 allows local users to affect availability via unknown vectors related to Kernel/VM.

CVE-2013-3757 sun vulnerability CVSS: 6.4 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect integrity and availability via vectors related to SMF/File Locking Services.

CVE-2013-3753 sun vulnerability CVSS: 7.8 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via vectors related to Kernel/STREAMS framework.

CVE-2013-3752 sun vulnerability CVSS: 4.3 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect integrity via vectors related to Service Management Facility (SMF).

CVE-2013-3750 sun vulnerability CVSS: 7.2 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/VM

CVE-2013-3748 sun vulnerability CVSS: 7.8 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 11 allows remote attackers to affect availability via vectors related to Driver/IDM (iSCSI Data Mover).

CVE-2013-3745 sun vulnerability CVSS: 2.1 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Libraries/Libc.

CVE-2013-0398 sun vulnerability CVSS: 5.0 17 Jul 2013, 13:41 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality via unknown vectors related to Utility/Remote Execution Server (in.rexecd).

CVE-2013-3743 sun vulnerability CVSS: 9.3 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 45 and earlier and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.

CVE-2013-2473 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.

CVE-2013-2472 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ShortBandedRaster size checks" in 2D.

CVE-2013-2471 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect IntegerComponentRaster size checks."

CVE-2013-2470 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "ImagingLib byte lookup processing."

CVE-2013-2469 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image layout verification" in 2D.

CVE-2013-2468 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2466.

CVE-2013-2467 sun vulnerability CVSS: 6.9 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 5.0 Update 45 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Java installer.

CVE-2013-2466 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2468.

CVE-2013-2465 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

CVE-2013-2464 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.

CVE-2013-2463 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image attribute verification" in 2D.

CVE-2013-2461 sun vulnerability CVSS: 7.5 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June and July 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass verification of XML signatures via vectors related to a "Missing check for [a] valid DOMCanonicalizationMethod canonicalization algorithm."

CVE-2013-2459 sun vulnerability CVSS: 10.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "integer overflow checks."

CVE-2013-2457 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to JMX. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is due to an incorrect implementation of "certain class checks" that allows remote attackers to bypass intended class restrictions.

CVE-2013-2456 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serialization. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper access checks for subclasses in the ObjectOutputStream class.

CVE-2013-2455 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2452. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect access checks by the (1) getEnclosingClass, (2) getEnclosingMethod, and (3) getEnclosingConstructor methods.

CVE-2013-2454 sun vulnerability CVSS: 5.8 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and integrity via vectors related to JDBC. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue does not properly restrict access to certain class packages in the SerialJavaObject class, which allows remote attackers to bypass the Java sandbox.

CVE-2013-2453 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect integrity via vectors related to JMX. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is due to a missing check for "package access" by the MBeanServer Introspector.

CVE-2013-2452 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2455. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "network address handling in virtual machine identifiers" and the lack of "unique and unpredictable IDs" in the java.rmi.dgc.VMID class.

CVE-2013-2451 sun vulnerability CVSS: 3.7 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper enforcement of exclusive port binds when running on Windows, which allows attackers to bind to ports that are already in use.

CVE-2013-2450 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Serialization. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper handling of circular references in ObjectStreamClass.

CVE-2013-2448 sun vulnerability CVSS: 7.6 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to insufficient "access restrictions" and "robustness of sound classes."

CVE-2013-2447 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to obtain a socket's local address via vectors involving inconsistencies between Socket.getLocalAddress and InetAddress.getLocalHost.

CVE-2013-2446 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via vectors related to CORBA. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue does not properly enforce access restrictions for CORBA output streams.

CVE-2013-2445 sun vulnerability CVSS: 7.8 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "handling of memory allocation errors."

CVE-2013-2444 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect availability via vectors related to AWT. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue does not "properly manage and restrict certain resources related to the processing of fonts," possibly involving temporary files.

CVE-2013-2443 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2452 and CVE-2013-2455. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is due to an incorrect "checking order" within the AccessControlContext class.

CVE-2013-2442 sun vulnerability CVSS: 7.5 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2466 and CVE-2013-2468.

CVE-2013-2437 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Deployment.

CVE-2013-2412 sun vulnerability CVSS: 5.0 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient indication of an SSL connection failure by JConsole, related to RMI connection dialog box.

CVE-2013-2407 sun vulnerability CVSS: 6.4 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "XML security and the class loader."

CVE-2013-1571 sun vulnerability CVSS: 4.3 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Javadoc. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to frame injection in HTML that is generated by Javadoc.

CVE-2013-1500 sun vulnerability CVSS: 3.6 18 Jun 2013, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to weak permissions for shared memory.

CVE-2013-2440 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.

CVE-2013-2439 sun vulnerability CVSS: 6.9 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Install.

CVE-2013-2435 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2440.

CVE-2013-2433 sun vulnerability CVSS: 4.3 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-1540.

CVE-2013-2432 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 and CVE-2013-1491.

CVE-2013-2430 sun vulnerability CVSS: 7.6 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "JPEGImageReader state corruption" when using native code.

CVE-2013-2429 sun vulnerability CVSS: 7.6 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "JPEGImageWriter state corruption" when using native code, which triggers memory corruption.

CVE-2013-2424 sun vulnerability CVSS: 5.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality via vectors related to JMX. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient class access checks" when "creating new instances" using MBeanInstantiator.

CVE-2013-2422 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.

CVE-2013-2420 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient "validation of images" in share/native/sun/awt/image/awt_ImageRep.c, possibly involving offsets.

CVE-2013-2419 sun vulnerability CVSS: 5.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font processing errors" in the International Components for Unicode (ICU) Layout Engine before 51.2.

CVE-2013-2418 sun vulnerability CVSS: 4.6 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2013-2417 sun vulnerability CVSS: 5.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to Networking. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an information leak involving InetAddress serialization. CVE has not investigated the apparent discrepancy between vendor reports regarding the impact of this issue.

CVE-2013-2394 sun vulnerability CVSS: 7.6 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2432 and CVE-2013-1491.

CVE-2013-2384 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font layout" in the International Components for Unicode (ICU) Layout Engine before 51.2.

CVE-2013-2383 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "handling of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.

CVE-2013-1569 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "checking of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.

CVE-2013-1563 sun vulnerability CVSS: 7.6 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.

CVE-2013-1558 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.

CVE-2013-1557 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "missing security restrictions" in the LogStream.setDefaultStream method.

CVE-2013-1540 sun vulnerability CVSS: 4.3 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2433.

CVE-2013-1537 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the default java.rmi.server.useCodebaseOnly setting of false, which allows remote attackers to perform "dynamic class downloading" and execute arbitrary code.

CVE-2013-1518 sun vulnerability CVSS: 10.0 17 Apr 2013, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXP. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "missing security restrictions."

CVE-2013-1530 sun vulnerability CVSS: 3.8 17 Apr 2013, 12:19 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.

CVE-2013-1507 sun vulnerability CVSS: 4.9 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Filesystem.

CVE-2013-1499 sun vulnerability CVSS: 1.7 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Network Configuration.

CVE-2013-1498 sun vulnerability CVSS: 4.9 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/IO, a different vulnerability than CVE-2013-1496.

CVE-2013-1496 sun vulnerability CVSS: 4.9 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/IO, a different vulnerability than CVE-2013-1498.

CVE-2013-1494 sun vulnerability CVSS: 4.7 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10, when running on SPARC T4 servers, allows local users to affect availability via unknown vectors related to Kernel.

CVE-2013-0413 sun vulnerability CVSS: 4.4 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Remote Execution Service.

CVE-2013-0412 sun vulnerability CVSS: 3.6 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect integrity and availability via unknown vectors related to Utility/pax.

CVE-2013-0411 sun vulnerability CVSS: 5.9 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via vectors related to RBAC Configuration.

CVE-2013-0408 sun vulnerability CVSS: 5.0 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to CPU performance counters drivers.

CVE-2013-0406 sun vulnerability CVSS: 4.3 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors via vectors related to Kernel/IPsec.

CVE-2013-0405 sun vulnerability CVSS: 6.4 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality and integrity via vectors related to NFS client mounts and IPv6.

CVE-2013-0404 sun vulnerability CVSS: 3.7 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Boot.

CVE-2013-0403 sun vulnerability CVSS: 1.9 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Utility.

CVE-2012-0570 sun vulnerability CVSS: 2.1 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Libraries/Libc.

CVE-2012-0568 sun vulnerability CVSS: 2.1 17 Apr 2013, 12:14 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality via unknown vectors related to Utility/fdformat.

CVE-2013-1493 sun vulnerability CVSS: 10.0 05 Mar 2013, 22:06 UTC

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

CVE-2013-0809 sun vulnerability CVSS: 10.0 05 Mar 2013, 22:06 UTC

Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.

CVE-2013-1487 sun vulnerability CVSS: 10.0 20 Feb 2013, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2013-1486 sun vulnerability CVSS: 10.0 20 Feb 2013, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CVE-2013-1481 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.

CVE-2013-1480 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.

CVE-2013-1479 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2013-1478 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" that can trigger an integer overflow and memory corruption.

CVE-2013-1476 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-0441 and CVE-2013-1475. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass Java sandbox restrictions via "certain value handler constructors."

CVE-2013-1475 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.

CVE-2013-1473 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVE-2013-0450 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper checks of "access control context" in the JMX RequiredModelMBean class.

CVE-2013-0446 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVE-2013-0445 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.

CVE-2013-0443 sun vulnerability CVSS: 4.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.

CVE-2013-0442 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.

CVE-2013-0441 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-1476 and CVE-2013-1475. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass Java sandbox restrictions via certain methods that should not be serialized, aka "missing serialization restriction."

CVE-2013-0440 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect availability via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to CPU consumption in the SSL/TLS implementation via a large number of ClientHello packets that are not properly handled by (1) ClientHandshaker.java and (2) ServerHandshaker.java.

CVE-2013-0438 sun vulnerability CVSS: 4.3 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.

CVE-2013-0435 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper restriction of com.sun.xml.internal packages and "Better handling of UI elements."

CVE-2013-0434 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.

CVE-2013-0433 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Networking. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to avoid triggering an exception during the deserialization of invalid InetSocketAddress data.

CVE-2013-0432 sun vulnerability CVSS: 6.4 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient clipboard access premission checks."

CVE-2013-0430 sun vulnerability CVSS: 6.9 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process of the client.

CVE-2013-0429 sun vulnerability CVSS: 7.6 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue involves the creation of a single PresentationManager that is shared across multiple thread groups, which allows remote attackers to bypass Java sandbox restrictions.

CVE-2013-0428 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect checks for proxy classes" in the Reflection API.

CVE-2013-0427 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Libraries. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to interrupt certain threads that should not be interrupted.

CVE-2013-0426 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.

CVE-2013-0425 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.

CVE-2013-0424 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.

CVE-2013-0423 sun vulnerability CVSS: 7.6 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVE-2013-0419 sun vulnerability CVSS: 7.6 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVE-2013-0409 sun vulnerability CVSS: 5.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38 allows remote attackers to affect confidentiality via vectors related to JMX.

CVE-2013-0351 sun vulnerability CVSS: 7.5 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVE-2012-3342 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVE-2012-3213 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

CVE-2012-1541 sun vulnerability CVSS: 10.0 02 Feb 2013, 00:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an interaction error in between the JRE plug-in for WebKit-based browsers and the Javascript engine, which allows remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements in a way that triggers an incorrect reference count and a use after free.

CVE-2013-0415 sun vulnerability CVSS: 6.0 17 Jan 2013, 01:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package.

CVE-2013-0414 sun vulnerability CVSS: 3.3 17 Jan 2013, 01:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via unknown vectors related to Utility/ksh93.

CVE-2013-0407 sun vulnerability CVSS: 4.6 17 Jan 2013, 01:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework.

CVE-2013-0400 sun vulnerability CVSS: 6.6 17 Jan 2013, 01:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Filesystem/cachefs.

CVE-2013-0399 sun vulnerability CVSS: 6.6 17 Jan 2013, 01:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Umount.

CVE-2012-3178 sun vulnerability CVSS: 2.1 17 Jan 2013, 01:55 UTC

Unspecified vulnerability in the kernel in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors.

CVE-2012-0569 sun vulnerability CVSS: 3.3 17 Jan 2013, 01:55 UTC

Unspecified vulnerability Oracle Sun Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Install/smpatch.

CVE-2012-4233 sun vulnerability CVSS: 4.3 19 Nov 2012, 12:10 UTC

LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.

CVE-2012-5095 sun vulnerability CVSS: 4.4 17 Oct 2012, 10:54 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to inetd.

CVE-2012-3215 sun vulnerability CVSS: 1.7 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11, when running on SPARC, allows local users to affect confidentiality via unknown vectors related to Kernel.

CVE-2012-3212 sun vulnerability CVSS: 4.7 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11, when running on SPARC T4 servers, allows local users to affect availability via unknown vectors related to Kernel.

CVE-2012-3211 sun vulnerability CVSS: 4.6 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/System Call.

CVE-2012-3210 sun vulnerability CVSS: 7.8 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via unknown vectors related to Kernel.

CVE-2012-3209 sun vulnerability CVSS: 5.6 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11, when running on SPARC, allows local users to affect integrity and availability via unknown vectors related to Logical Domain (LDOM).

CVE-2012-3208 sun vulnerability CVSS: 4.9 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability, related to Kernel/RCTL.

CVE-2012-3207 sun vulnerability CVSS: 4.9 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 9, 10, and 11 allows local users to affect availability via unknown vectors related to Kernel.

CVE-2012-3205 sun vulnerability CVSS: 2.1 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity via unknown vectors related to Vino server.

CVE-2012-3204 sun vulnerability CVSS: 7.2 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management.

CVE-2012-3203 sun vulnerability CVSS: 2.1 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability, related to Gnome Display Manager GDM.

CVE-2012-3199 sun vulnerability CVSS: 7.2 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Gnome Trusted Extension.

CVE-2012-3189 sun vulnerability CVSS: 7.8 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability, related to COMSTAR.

CVE-2012-3187 sun vulnerability CVSS: 6.9 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

CVE-2012-3165 sun vulnerability CVSS: 3.6 17 Oct 2012, 00:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality and integrity via unknown vectors related to mailx.

CVE-2012-3155 sun vulnerability CVSS: 5.0 16 Oct 2012, 23:55 UTC

Unspecified vulnerability in the CORBA ORB component in Sun GlassFish Enterprise Server 2.1.1, Oracle GlassFish Server 3.0.1 and 3.1.2, and Sun Java System Application Server 8.1 and 8.2 allows remote attackers to affect availability, related to CORBA ORB.

CVE-2012-5089 sun vulnerability CVSS: 7.6 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-3143.

CVE-2012-5086 sun vulnerability CVSS: 10.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.

CVE-2012-5085 sun vulnerability CVSS: 0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote authenticated users to have an unspecified impact via unknown vectors related to Networking. NOTE: the Oracle CPU states that this issue has a 0.0 CVSS score. If so, then this is not a vulnerability and this issue should not be included in CVE.

CVE-2012-5084 sun vulnerability CVSS: 7.6 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

CVE-2012-5083 sun vulnerability CVSS: 10.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, 1.4.2_38 and earlier, and JavaFX 2.2 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2012-5081 sun vulnerability CVSS: 5.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect availability, related to JSSE.

CVE-2012-5079 sun vulnerability CVSS: 5.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect integrity via unknown vectors related to Libraries, a different vulnerability than CVE-2012-5073.

CVE-2012-5077 sun vulnerability CVSS: 2.6 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Security.

CVE-2012-5075 sun vulnerability CVSS: 5.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, related to JMX.

CVE-2012-5073 sun vulnerability CVSS: 5.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect integrity via unknown vectors related to Libraries, a different vulnerability than CVE-2012-5079.

CVE-2012-5072 sun vulnerability CVSS: 5.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality via unknown vectors related to Security.

CVE-2012-5071 sun vulnerability CVSS: 6.4 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality and integrity, related to JMX.

CVE-2012-5069 sun vulnerability CVSS: 5.8 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Concurrency.

CVE-2012-5068 sun vulnerability CVSS: 7.5 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

CVE-2012-4416 sun vulnerability CVSS: 6.4 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Hotspot.

CVE-2012-3216 sun vulnerability CVSS: 2.6 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

CVE-2012-3159 sun vulnerability CVSS: 7.5 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-1533.

CVE-2012-3143 sun vulnerability CVSS: 10.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX, a different vulnerability than CVE-2012-5089.

CVE-2012-1533 sun vulnerability CVSS: 10.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2012-3159.

CVE-2012-1532 sun vulnerability CVSS: 10.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2012-1531 sun vulnerability CVSS: 10.0 16 Oct 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier; and JavaFX 2.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2012-0547 sun vulnerability CVSS: 0 30 Aug 2012, 23:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and 6 Update 34 and earlier, has no impact and remote attack vectors involving AWT and "a security-in-depth issue that is not directly exploitable but which can be used to aggravate security vulnerabilities that can be directly exploited." NOTE: this identifier was assigned by the Oracle CNA, but CVE is not intended to cover defense-in-depth issues that are only exposed by the presence of other vulnerabilities. NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "toolkit internals references."

CVE-2012-4298 sun vulnerability CVSS: 5.4 16 Aug 2012, 10:38 UTC

Integer signedness error in the vwr_read_rec_data_ethernet function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to execute arbitrary code via a crafted packet-trace file that triggers a buffer overflow.

CVE-2012-4297 sun vulnerability CVSS: 8.3 16 Aug 2012, 10:38 UTC

Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in Wireshark 1.6.x before 1.6.10 and 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a malformed packet.

CVE-2012-4296 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

Buffer overflow in epan/dissectors/packet-rtps2.c in the RTPS2 dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet.

CVE-2012-4295 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial of service (application crash) via a crafted speed (aka rate) value.

CVE-2012-4294 sun vulnerability CVSS: 5.8 16 Aug 2012, 10:38 UTC

Buffer overflow in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to execute arbitrary code via a large speed (aka rate) value.

CVE-2012-4293 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

plugins/ethercat/packet-ecatmb.c in the EtherCAT Mailbox dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly handle certain integer fields, which allows remote attackers to cause a denial of service (application exit) via a malformed packet.

CVE-2012-4292 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with key-destruction behavior in a certain tree library, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

CVE-2012-4291 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

CVE-2012-4290 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a malformed packet.

CVE-2012-4289 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries.

CVE-2012-4288 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop or application crash) via a large value for a span length.

CVE-2012-4287 sun vulnerability CVSS: 5.0 16 Aug 2012, 10:38 UTC

epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length.

CVE-2012-4286 sun vulnerability CVSS: 4.3 16 Aug 2012, 10:38 UTC

The pcapng_read_packet_block function in wiretap/pcapng.c in the pcap-ng file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted pcap-ng file.

CVE-2012-4285 sun vulnerability CVSS: 3.3 16 Aug 2012, 10:38 UTC

The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.

CVE-2012-3131 sun vulnerability CVSS: 4.3 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 9, 10, and 11 allows remote attackers to affect confidentiality, related to Network/NFS.

CVE-2012-3130 sun vulnerability CVSS: 4.3 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.

CVE-2012-3129 sun vulnerability CVSS: 5.1 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, integrity, and availability, related to Gnome PDF viewer.

CVE-2012-3127 sun vulnerability CVSS: 5.4 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to SCTP.

CVE-2012-3125 sun vulnerability CVSS: 7.1 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows remote attackers to affect availability, related to TCP/IP.

CVE-2012-3124 sun vulnerability CVSS: 5.0 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.

CVE-2012-3123 sun vulnerability CVSS: 5.0 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.

CVE-2012-3122 sun vulnerability CVSS: 2.6 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.

CVE-2012-3121 sun vulnerability CVSS: 5.0 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows remote attackers to affect availability via unknown vectors related to in.tnamed and NameServer.

CVE-2012-3120 sun vulnerability CVSS: 7.8 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8 allows remote attackers to affect availability, related to TCP/IP.

CVE-2012-3112 sun vulnerability CVSS: 4.3 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Solaris Management Console.

CVE-2012-1765 sun vulnerability CVSS: 4.7 17 Jul 2012, 23:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect integrity via unknown vectors related to Branded Zone.

CVE-2012-1752 sun vulnerability CVSS: 4.9 17 Jul 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability, related to Kernel/NFS.

CVE-2012-1750 sun vulnerability CVSS: 4.4 17 Jul 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to mailx.

CVE-2012-1687 sun vulnerability CVSS: 5.6 17 Jul 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability, related to Logical Domains (LDOM).

CVE-2012-0563 sun vulnerability CVSS: 2.1 17 Jul 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11 allows local users to affect availability via unknown vectors related to Kerberos/klist.

CVE-2012-1725 sun vulnerability CVSS: 10.0 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVE-2012-1724 sun vulnerability CVSS: 5.0 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, and 6 update 32 and earlier, allows remote attackers to affect availability, related to JAXP.

CVE-2012-1720 sun vulnerability CVSS: 3.7 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier, when running on Solaris, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Networking.

CVE-2012-1719 sun vulnerability CVSS: 5.0 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect integrity, related to CORBA.

CVE-2012-1718 sun vulnerability CVSS: 5.0 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

CVE-2012-1716 sun vulnerability CVSS: 10.0 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

CVE-2012-1713 sun vulnerability CVSS: 10.0 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2012-1711 sun vulnerability CVSS: 7.5 16 Jun 2012, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to CORBA.

CVE-2012-0217 sun vulnerability CVSS: 7.2 12 Jun 2012, 22:55 UTC

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

CVE-2012-0507 sun vulnerability CVSS: 10.0 07 Jun 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVE-2012-1698 sun vulnerability CVSS: 2.1 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote authenticated users to affect confidentiality, related to Kernel/GLD.

CVE-2012-1695 sun vulnerability CVSS: 10.0 03 May 2012, 22:55 UTC

Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2012-1694 sun vulnerability CVSS: 6.4 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality and integrity, related to libsasl.

CVE-2012-1692 sun vulnerability CVSS: 4.9 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability, related to SCTP.

CVE-2012-1691 sun vulnerability CVSS: 6.6 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Privileges.

CVE-2012-1684 sun vulnerability CVSS: 4.3 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Password Policy.

CVE-2012-1683 sun vulnerability CVSS: 5.9 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to gssd.

CVE-2012-1681 sun vulnerability CVSS: 4.9 03 May 2012, 22:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Kernel/sockfs.

CVE-2012-0551 sun vulnerability CVSS: 5.8 03 May 2012, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE 7 update 4 and earlier and 6 update 32 and earlier, and the GlassFish Enterprise Server component in Oracle Sun Products Suite GlassFish Enterprise Server 3.1.1, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Container or Deployment.

CVE-2012-0539 sun vulnerability CVSS: 6.2 03 May 2012, 18:55 UTC

Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to (1) bsmconv and (2) bsmunconv.

CVE-2012-0506 sun vulnerability CVSS: 4.3 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to CORBA.

CVE-2012-0505 sun vulnerability CVSS: 7.5 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.

CVE-2012-0504 sun vulnerability CVSS: 9.3 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install and the Java Update mechanism.

CVE-2012-0503 sun vulnerability CVSS: 7.5 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to I18n.

CVE-2012-0502 sun vulnerability CVSS: 6.4 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and availability, related to AWT.

CVE-2012-0501 sun vulnerability CVSS: 5.0 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect availability via unknown vectors.

CVE-2012-0500 sun vulnerability CVSS: 10.0 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and JavaFX 2.0.2 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2012-0499 sun vulnerability CVSS: 10.0 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier; and JavaFX 2.0.2 and earlier; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2012-0498 sun vulnerability CVSS: 10.0 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2012-0497 sun vulnerability CVSS: 10.0 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, and 6 Update 30 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2011-3563 sun vulnerability CVSS: 6.4 15 Feb 2012, 22:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, 5.0 Update 33 and earlier, and 1.4.2_35 and earlier allows remote attackers to affect confidentiality and availability via unknown vectors related to Sound.

CVE-2012-0109 sun vulnerability CVSS: 3.6 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality and availability, related to TCP/IP.

CVE-2012-0103 sun vulnerability CVSS: 4.9 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to Kernel.

CVE-2012-0100 sun vulnerability CVSS: 6.8 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kerberos.

CVE-2012-0099 sun vulnerability CVSS: 2.6 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to sshd.

CVE-2012-0098 sun vulnerability CVSS: 1.9 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2011-0813.

CVE-2012-0097 sun vulnerability CVSS: 2.1 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect confidentiality via unknown vectors related to ksh93 Shell.

CVE-2012-0096 sun vulnerability CVSS: 5.0 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Network.

CVE-2012-0094 sun vulnerability CVSS: 7.8 18 Jan 2012, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability, related to TCP/IP.

CVE-2011-2713 sun vulnerability CVSS: 4.3 21 Oct 2011, 18:55 UTC

oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser.

CVE-2011-3561 sun vulnerability CVSS: 1.8 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.

CVE-2011-3560 sun vulnerability CVSS: 6.4 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.

CVE-2011-3558 sun vulnerability CVSS: 5.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to HotSpot.

CVE-2011-3557 sun vulnerability CVSS: 6.8 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3556.

CVE-2011-3556 sun vulnerability CVSS: 7.5 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI, a different vulnerability than CVE-2011-3557.

CVE-2011-3555 sun vulnerability CVSS: 6.1 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, and 7 allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity and availability via unknown vectors.

CVE-2011-3554 sun vulnerability CVSS: 10.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2011-3553 sun vulnerability CVSS: 3.5 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote authenticated users to affect confidentiality, related to JAXWS.

CVE-2011-3552 sun vulnerability CVSS: 2.6 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote attackers to affect integrity via unknown vectors related to Networking.

CVE-2011-3551 sun vulnerability CVSS: 9.3 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2011-3550 sun vulnerability CVSS: 7.6 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.

CVE-2011-3549 sun vulnerability CVSS: 10.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

CVE-2011-3548 sun vulnerability CVSS: 10.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.

CVE-2011-3547 sun vulnerability CVSS: 5.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Networking.

CVE-2011-3546 sun vulnerability CVSS: 5.8 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to Deployment.

CVE-2011-3545 sun vulnerability CVSS: 10.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.

CVE-2011-3521 sun vulnerability CVSS: 10.0 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE, 7, 6 Update 27 and earlier, and 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deserialization.

CVE-2011-3516 sun vulnerability CVSS: 7.6 19 Oct 2011, 21:55 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2011-3543 sun vulnerability CVSS: 7.8 18 Oct 2011, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to iSCSI DataMover (IDM).

CVE-2011-3542 sun vulnerability CVSS: 4.9 18 Oct 2011, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to Kernel/Performance Counter BackEnd Module (pcbe).

CVE-2011-3515 sun vulnerability CVSS: 5.6 18 Oct 2011, 22:55 UTC

Unspecified vulnerability in the Oracle Solaris 10 and 11 Express allows local users to affect integrity and availability via unknown vectors related to Process File System (procfs).

CVE-2011-3508 sun vulnerability CVSS: 9.3 18 Oct 2011, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect confidentiality, integrity, and availability, related to LDAP library.

CVE-2011-2313 sun vulnerability CVSS: 4.3 18 Oct 2011, 22:55 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to ZFS, a different vulnerability than CVE-2011-2311.

CVE-2008-7300 sun vulnerability CVSS: 8.5 05 Oct 2011, 02:56 UTC

The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is in the installed state, allows remote authenticated users to bypass a Mandatory Access Control (MAC) policy and obtain access to the global zone.

CVE-2011-2298 sun vulnerability CVSS: 5.0 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to KSSL.

CVE-2011-2296 sun vulnerability CVSS: 4.9 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, related to Kernel/SCTP.

CVE-2011-2295 sun vulnerability CVSS: 4.7 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability, related to Driver/USB.

CVE-2011-2294 sun vulnerability CVSS: 5.0 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote attackers to affect availability, related to SSH.

CVE-2011-2293 sun vulnerability CVSS: 4.9 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to Zones.

CVE-2011-2291 sun vulnerability CVSS: 1.7 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality via unknown vectors related to Trusted Extensions.

CVE-2011-2290 sun vulnerability CVSS: 4.9 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel/sockfs.

CVE-2011-2289 sun vulnerability CVSS: 3.6 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect integrity and availability via unknown vectors related to LiveUpgrade.

CVE-2011-2287 sun vulnerability CVSS: 7.8 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to fingerd.

CVE-2011-2285 sun vulnerability CVSS: 7.2 21 Jul 2011, 00:55 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Installer.

CVE-2011-2259 sun vulnerability CVSS: 4.9 20 Jul 2011, 23:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability, related to UFS.

CVE-2011-2258 sun vulnerability CVSS: 4.6 20 Jul 2011, 23:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rksh.

CVE-2011-2249 sun vulnerability CVSS: 5.2 20 Jul 2011, 23:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote authenticated users to affect availability, related to TCP/IP.

CVE-2011-0873 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2011-0872 sun vulnerability CVSS: 5.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote attackers to affect availability via unknown vectors related to NIO.

CVE-2011-0871 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.

CVE-2011-0869 sun vulnerability CVSS: 5.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 26 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to SAAJ.

CVE-2011-0868 sun vulnerability CVSS: 5.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.

CVE-2011-0867 sun vulnerability CVSS: 5.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Networking.

CVE-2011-0866 sun vulnerability CVSS: 7.6 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Java Runtime Environment.

CVE-2011-0865 sun vulnerability CVSS: 2.6 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Deserialization.

CVE-2011-0864 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.

CVE-2011-0863 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2011-0862 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

CVE-2011-0817 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2011-0815 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to AWT.

CVE-2011-0814 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound, a different vulnerability than CVE-2011-0802.

CVE-2011-0802 sun vulnerability CVSS: 10.0 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound, a different vulnerability than CVE-2011-0814.

CVE-2011-0788 sun vulnerability CVSS: 7.6 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0786.

CVE-2011-0786 sun vulnerability CVSS: 7.6 14 Jun 2011, 18:55 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0788.

CVE-2011-0841 sun vulnerability CVSS: 7.8 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to TCP/IP.

CVE-2011-0839 sun vulnerability CVSS: 3.7 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect availability, related to LOFS.

CVE-2011-0829 sun vulnerability CVSS: 4.9 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability, related to Kernel/SPARC.

CVE-2011-0821 sun vulnerability CVSS: 3.0 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors related to uucp.

CVE-2011-0820 sun vulnerability CVSS: 5.4 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in Oracle Solaris 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Kernel.

CVE-2011-0813 sun vulnerability CVSS: 4.9 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2012-0098.

CVE-2011-0812 sun vulnerability CVSS: 3.7 20 Apr 2011, 10:55 UTC

Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect availability via unknown vectors related to Kernel.

CVE-2011-0807 sun vulnerability CVSS: 10.0 20 Apr 2011, 03:14 UTC

Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration.

CVE-2011-0801 sun vulnerability CVSS: 3.6 20 Apr 2011, 03:14 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect confidentiality and integrity via unknown vectors related to cp.

CVE-2011-0800 sun vulnerability CVSS: 6.5 20 Apr 2011, 03:14 UTC

Unspecified vulnerability in the Solaris component in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Administration Utilities.

CVE-2011-0790 sun vulnerability CVSS: 1.7 20 Apr 2011, 03:14 UTC

Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality via unknown vectors related to wbem.

CVE-2011-0412 sun vulnerability CVSS: 2.1 19 Apr 2011, 19:55 UTC

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

CVE-2011-0706 sun vulnerability CVSS: 7.5 19 Feb 2011, 01:00 UTC

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."

CVE-2010-4476 sun vulnerability CVSS: 5.0 17 Feb 2011, 19:00 UTC

The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

CVE-2010-4475 sun vulnerability CVSS: 4.3 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than CVE-2010-4447.

CVE-2010-4474 sun vulnerability CVSS: 2.1 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java DB component in Oracle Java SE and Java for Business 6 Update 23, and, and earlier allows local users to affect confidentiality via unknown vectors related to Security, a similar vulnerability to CVE-2009-4269.

CVE-2010-4473 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-4454 and CVE-2010-4462.

CVE-2010-4472 sun vulnerability CVSS: 2.6 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations."

CVE-2010-4471 sun vulnerability CVSS: 5.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to 2D. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the exposure of system properties via vectors related to Font.createFont and exception text.

CVE-2010-4470 sun vulnerability CVSS: 5.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23, and, and earlier allows remote attackers to affect availability via unknown vectors related to JAXP and unspecified APIs. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to "Features set on SchemaFactory not inherited by Validator."

CVE-2010-4469 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is heap corruption related to the Verifier and "backward jsrs."

CVE-2010-4468 sun vulnerability CVSS: 4.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, and 5.0 Update 27 and earlier, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity via unknown vectors related to JDBC.

CVE-2010-4467 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 10 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2010-4466 sun vulnerability CVSS: 5.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Windows, Solaris, and, Linux; 5.0 Update 27 and earlier for Windows; and 1.4.2_29 and earlier for Windows allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.

CVE-2010-4465 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the lack of framework support by AWT event dispatch, and/or "clipboard access in Applets."

CVE-2010-4463 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 21 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2010-4462 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-4454 and CVE-2010-4473.

CVE-2010-4454 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound and unspecified APIs, a different vulnerability than CVE-2010-4462 and CVE-2010-4473.

CVE-2010-4452 sun vulnerability CVSS: 10.0 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-4451 sun vulnerability CVSS: 7.6 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Windows, when using Java Update, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.

CVE-2010-4450 sun vulnerability CVSS: 3.7 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier for Solaris and Linux; 5.0 Update 27 and earlier for Solaris and Linux; and 1.4.2_29 and earlier for Solaris and Linux allows local standalone applications to affect confidentiality, integrity, and availability via unknown vectors related to Launcher. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is an untrusted search path vulnerability involving an empty LD_LIBRARY_PATH environment variable.

CVE-2010-4448 sun vulnerability CVSS: 2.6 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect integrity via unknown vectors related to Networking. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves "DNS cache poisoning by untrusted applets."

CVE-2010-4447 sun vulnerability CVSS: 4.3 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment, a different vulnerability than CVE-2010-4475.

CVE-2010-4422 sun vulnerability CVSS: 7.6 17 Feb 2011, 19:00 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVE-2010-4460 sun vulnerability CVSS: 3.6 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Fault Manager Daemon.

CVE-2010-4459 sun vulnerability CVSS: 4.6 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to SCTP and Kernel/sockfs.

CVE-2010-4458 sun vulnerability CVSS: 4.1 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability, related to ZFS.

CVE-2010-4457 sun vulnerability CVSS: 7.8 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows remote attackers to affect availability, related to SMB and CIFS.

CVE-2010-4456 sun vulnerability CVSS: 4.3 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to affect integrity via unknown vectors related to Web Mail.

CVE-2010-4446 sun vulnerability CVSS: 4.6 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 11 Express allows local users to affect availability via unknown vectors related to RDS and Kernel/InfiniBand.

CVE-2010-4444 sun vulnerability CVSS: 6.8 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-4443 sun vulnerability CVSS: 4.4 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability, related to Kernel/NFS.

CVE-2010-4442 sun vulnerability CVSS: 4.4 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.

CVE-2010-4440 sun vulnerability CVSS: 4.4 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle 10 and 11 Express allows local users to affect availability via unknown vectors related to the Kernel.

CVE-2010-4435 sun vulnerability CVSS: 10.0 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.

CVE-2010-4433 sun vulnerability CVSS: 5.0 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality via unknown vectors related to Ethernet and the Driver sub-component.

CVE-2010-4431 sun vulnerability CVSS: 1.0 19 Jan 2011, 17:00 UTC

Unspecified vulnerability in Oracle Sun Java System Portal Server 7.1 and 7.2 allows local users to affect confidentiality via unknown vectors related to Proxy.

CVE-2010-4415 sun vulnerability CVSS: 4.1 19 Jan 2011, 16:00 UTC

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to libc.

CVE-2010-3586 sun vulnerability CVSS: 3.6 19 Jan 2011, 16:00 UTC

Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.

CVE-2010-2632 sun vulnerability CVSS: 7.8 19 Jan 2011, 16:00 UTC

Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.

CVE-2010-3574 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.

CVE-2010-3573 sun vulnerability CVSS: 5.1 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to missing validation of request headers in the HttpURLConnection class when they are set by applets, which allows remote attackers to bypass the intended security policy.

CVE-2010-3572 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-3571 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.

CVE-2010-3570 sun vulnerability CVSS: 7.6 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-3569 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this allows remote attackers to execute arbitrary code by causing the defaultReadObject method in the Serialization API to set a volatile field multiple times.

CVE-2010-3568 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is a race condition related to deserialization.

CVE-2010-3567 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to a calculation error in right-to-left text character counts for the ICU OpenType font rendering implementation, which triggers an out-of-bounds memory access.

CVE-2010-3566 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update and 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow that leads to a buffer overflow via a crafted devs (device information) tag structure in a color profile.

CVE-2010-3565 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow that triggers memory corruption via large values in a subsample of a JPEG image, related to JPEGImageWriter.writeImage in the imageio API.

CVE-2010-3563 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to "how Web Start retrieves security policies," BasicServiceImpl, and forged policies that bypass sandbox restrictions.

CVE-2010-3562 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is a double free vulnerability in IndexColorModel that allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.

CVE-2010-3561 sun vulnerability CVSS: 7.5 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this involves the use of the privileged accept method in the ServerSocket class, which does not limit which hosts can connect and allows remote attackers to bypass intended network access restrictions.

CVE-2010-3560 sun vulnerability CVSS: 2.6 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.

CVE-2010-3559 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this involves an incorrect sign extension in the HeadspaceSoundbank.nGetName function, which allows attackers to execute arbitrary code via a crafted BANK record that leads to a buffer overflow.

CVE-2010-3558 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-3557 sun vulnerability CVSS: 6.8 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to the modification of "behavior and state of certain JDK classes" and "mutable static."

CVE-2010-3556 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-3555 sun vulnerability CVSS: 9.3 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that the ActiveX Plugin does not properly initialize an object field that is used as a window handle, which allows attackers to execute arbitrary code.

CVE-2010-3554 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to "permissions granted to certain system objects."

CVE-2010-3553 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to unsafe reflection involving the UIDefault.ProxyLazyValue class.

CVE-2010-3552 sun vulnerability CVSS: 10.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-3551 sun vulnerability CVSS: 5.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown vectors.

CVE-2010-3550 sun vulnerability CVSS: 9.3 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-3549 sun vulnerability CVSS: 6.8 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is an HTTP request splitting vulnerability involving the handling of the chunked transfer encoding method by the HttpURLConnection class.

CVE-2010-3548 sun vulnerability CVSS: 5.0 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this allows remote attackers to determine internal IP addresses or "otherwise-protected internal network names."

CVE-2010-3541 sun vulnerability CVSS: 5.1 19 Oct 2010, 22:00 UTC

Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to missing validation of request headers in the HttpURLConnection class when they are set by applets, which allows remote attackers to bypass the intended security policy.

CVE-2009-4774 sun vulnerability CVSS: 4.0 21 Apr 2010, 14:30 UTC

Unspecified vulnerability in Sun Solaris 10 and OpenSolaris snv_49 through snv_117, when 64bit mode is used on the Intel x86 platform and a Linux (lx) branded zone is configured, allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2007-6225.

CVE-2010-0887 sun vulnerability CVSS: 10.0 20 Apr 2010, 19:30 UTC

Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0886 sun vulnerability CVSS: 10.0 20 Apr 2010, 19:30 UTC

Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-1227 sun vulnerability CVSS: 4.3 01 Apr 2010, 22:30 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF) attack involving the cmd and argv parameters to cmd.msc.

CVE-2010-0850 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0849 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.

CVE-2010-0848 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0847 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows arbitrary code execution via a crafted image.

CVE-2010-0846 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows remote attackers to execute arbitrary code, related to an "invalid assignment" and inconsistent length values in a JPEG image encoder (JPEGImageEncoderImpl).

CVE-2010-0845 sun vulnerability CVSS: 5.1 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0844 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is for improper parsing of a crafted MIDI stream when creating a MixerSequencer object, which causes a pointer to be corrupted and allows a NULL byte to be written to arbitrary memory.

CVE-2010-0843 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.

CVE-2010-0842 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.

CVE-2010-0841 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the Java Runtime Environment that allows remote attackers to execute arbitrary code via a JPEG image that contains subsample dimensions with large values, related to JPEGImageReader and "stepX".

CVE-2010-0839 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0838 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.

CVE-2010-0837 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0095 sun vulnerability CVSS: 6.8 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0093.

CVE-2010-0094 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.

CVE-2010-0093 sun vulnerability CVSS: 5.1 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0095.

CVE-2010-0092 sun vulnerability CVSS: 5.1 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0091 sun vulnerability CVSS: 4.3 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-0084.

CVE-2010-0090 sun vulnerability CVSS: 5.8 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18 allows remote attackers to affect integrity and availability via unknown vectors.

CVE-2010-0089 sun vulnerability CVSS: 5.0 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect availability via unknown vectors.

CVE-2010-0088 sun vulnerability CVSS: 6.8 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0085.

CVE-2010-0087 sun vulnerability CVSS: 7.5 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-0085 sun vulnerability CVSS: 5.1 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0088.

CVE-2010-0084 sun vulnerability CVSS: 5.0 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-0091.

CVE-2010-0082 sun vulnerability CVSS: 5.1 01 Apr 2010, 16:30 UTC

Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

CVE-2010-1183 sun vulnerability CVSS: 3.3 29 Mar 2010, 22:30 UTC

Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.

CVE-2010-0708 sun vulnerability CVSS: 5.0 25 Feb 2010, 19:30 UTC

Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP search request.

CVE-2003-1590 sun vulnerability CVSS: 5.0 25 Feb 2010, 19:30 UTC

Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors.

CVE-2003-1589 sun vulnerability CVSS: 5.0 25 Feb 2010, 19:30 UTC

Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors.

CVE-2003-1588 sun vulnerability CVSS: 1.9 08 Feb 2010, 20:30 UTC

Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.

CVE-2010-0559 sun vulnerability CVSS: 7.5 05 Feb 2010, 22:30 UTC

The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.

CVE-2010-0558 sun vulnerability CVSS: 7.5 05 Feb 2010, 22:30 UTC

The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.

CVE-2003-1579 sun vulnerability CVSS: 4.3 05 Feb 2010, 22:30 UTC

Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

CVE-2003-1578 sun vulnerability CVSS: 4.3 05 Feb 2010, 22:30 UTC

Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

CVE-2003-1577 sun vulnerability CVSS: 2.6 05 Feb 2010, 22:30 UTC

Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a crafted DNS response, related to an "Inverse Lookup Log Corruption (ILLC)" issue, a different vulnerability than CVE-2002-1315 and CVE-2002-1316.

CVE-2010-0453 sun vulnerability CVSS: 4.9 03 Feb 2010, 18:30 UTC

The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.

CVE-2005-4885 sun vulnerability CVSS: 7.5 28 Jan 2010, 20:30 UTC

Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.

CVE-2004-2766 sun vulnerability CVSS: 4.3 28 Jan 2010, 20:30 UTC

Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.

CVE-2004-2765 sun vulnerability CVSS: 4.3 28 Jan 2010, 20:30 UTC

Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.

CVE-2003-1576 sun vulnerability CVSS: 10.0 28 Jan 2010, 20:30 UTC

Buffer overflow in pamverifier in Change Manager (CM) 1.0 for Sun Management Center (SunMC) 3.0 on Solaris 8 and 9 on the sparc platform allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2010-0389 sun vulnerability CVSS: 5.0 25 Jan 2010, 19:30 UTC

The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token.

CVE-2010-0388 sun vulnerability CVSS: 7.5 25 Jan 2010, 19:30 UTC

Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.

CVE-2010-0387 sun vulnerability CVSS: 7.5 25 Jan 2010, 19:30 UTC

Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.

CVE-2010-0386 sun vulnerability CVSS: 4.3 25 Jan 2010, 19:30 UTC

The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

CVE-2010-0361 sun vulnerability CVSS: 10.0 20 Jan 2010, 16:30 UTC

Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.

CVE-2010-0360 sun vulnerability CVSS: 10.0 20 Jan 2010, 16:30 UTC

Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and CVE-2010-0273.

CVE-2010-0313 sun vulnerability CVSS: 5.0 14 Jan 2010, 19:30 UTC

The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message.

CVE-2010-0311 sun vulnerability CVSS: 6.8 14 Jan 2010, 19:30 UTC

Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manager is used, allows remote attackers to obtain administrative access via unknown vectors.

CVE-2010-0310 sun vulnerability CVSS: 6.8 14 Jan 2010, 19:30 UTC

Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.

CVE-2010-0273 sun vulnerability CVSS: 7.5 08 Jan 2010, 17:30 UTC

Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2010-0272 sun vulnerability CVSS: 7.5 08 Jan 2010, 17:30 UTC

Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2010-0271 sun vulnerability CVSS: 4.6 08 Jan 2010, 17:30 UTC

hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.

CVE-2009-4443 sun vulnerability CVSS: 4.3 28 Dec 2009, 19:30 UTC

Unspecified vulnerability in the psearch (aka persistent search) functionality in Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allows remote attackers to cause a denial of service (psearch outage) by using a crafted psearch client to send requests that trigger a psearch thread loop, aka Bug Id 6855978.

CVE-2009-4442 sun vulnerability CVSS: 5.0 28 Dec 2009, 19:30 UTC

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no operations on these connections, aka Bug Id 6648665.

CVE-2009-4441 sun vulnerability CVSS: 5.0 28 Dec 2009, 19:30 UTC

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not enable the SO_KEEPALIVE socket option, which makes it easier for remote attackers to cause a denial of service (connection slot exhaustion) via multiple connections, aka Bug Id 6782659.

CVE-2009-4440 sun vulnerability CVSS: 6.8 28 Dec 2009, 19:30 UTC

Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593.

CVE-2009-4314 sun vulnerability CVSS: 4.4 14 Dec 2009, 17:30 UTC

Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device.

CVE-2009-4295 sun vulnerability CVSS: 7.8 11 Dec 2009, 16:30 UTC

Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic.

CVE-2009-4294 sun vulnerability CVSS: 10.0 11 Dec 2009, 16:30 UTC

Unspecified vulnerability in the Authentication Manager (aka utauthd) in Sun Ray Server Software 4.0 and 4.1 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.

CVE-2009-4226 sun vulnerability CVSS: 7.1 08 Dec 2009, 18:30 UTC

Race condition in the IP module in the kernel in Sun OpenSolaris snv_106 through snv_124 allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors related to the (1) tcp_do_getsockname or (2) tcp_do_getpeername function.

CVE-2009-4191 sun vulnerability CVSS: 7.2 03 Dec 2009, 17:30 UTC

Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated by the vd_sol_local module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-4190 sun vulnerability CVSS: 7.8 03 Dec 2009, 17:30 UTC

Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause a denial of service (panic) via unknown vectors, as demonstrated by the vd_solaris2 module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-4187 sun vulnerability CVSS: 4.3 03 Dec 2009, 17:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-4080 sun vulnerability CVSS: 2.1 29 Nov 2009, 13:07 UTC

Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 and 10, and OpenSolaris before snv_78, allow local users to cause a denial of service (daemon crash) via vectors involving multiple serviceSearchDescriptor attributes and a call to the getldap_lookup function, and unspecified other vectors.

CVE-2009-4075 sun vulnerability CVSS: 5.0 25 Nov 2009, 18:30 UTC

Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors that trigger a "dangling sshd authentication thread."

CVE-2009-3940 sun vulnerability CVSS: 2.1 16 Nov 2009, 19:30 UTC

Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and Sun VirtualBox before 3.0.10, allows guest OS users to cause a denial of service (memory consumption) on the guest OS via unknown vectors.

CVE-2009-3937 sun vulnerability CVSS: 4.9 13 Nov 2009, 16:30 UTC

Memory leak in Solaris TCP sockets in Sun OpenSolaris snv_106 through snv_126 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors involving tcp_sendmsg processing "ancillary data."

CVE-2009-3923 sun vulnerability CVSS: 7.5 10 Nov 2009, 00:30 UTC

The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.

CVE-2009-3886 sun vulnerability CVSS: 7.5 09 Nov 2009, 19:30 UTC

The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531.

CVE-2009-3885 sun vulnerability CVSS: 5.0 09 Nov 2009, 19:30 UTC

Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a related issue to CVE-2007-2789, aka Bug Id 6632445.

CVE-2009-3884 sun vulnerability CVSS: 5.0 09 Nov 2009, 19:30 UTC

The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.

CVE-2009-3883 sun vulnerability CVSS: 7.5 09 Nov 2009, 19:30 UTC

Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657138.

CVE-2009-3882 sun vulnerability CVSS: 7.5 09 Nov 2009, 19:30 UTC

Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657026.

CVE-2009-3881 sun vulnerability CVSS: 7.5 09 Nov 2009, 19:30 UTC

Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650.

CVE-2009-3880 sun vulnerability CVSS: 5.0 09 Nov 2009, 19:30 UTC

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.

CVE-2009-3879 sun vulnerability CVSS: 7.5 09 Nov 2009, 19:30 UTC

Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.

CVE-2009-3729 sun vulnerability CVSS: 5.0 09 Nov 2009, 19:30 UTC

Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash) via a certain test suite, aka Bug Id 6815780.

CVE-2009-3728 sun vulnerability CVSS: 5.0 09 Nov 2009, 19:30 UTC

Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.

CVE-2009-3899 sun vulnerability CVSS: 7.8 06 Nov 2009, 15:30 UTC

Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 through snv_94, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVE-2009-3878 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco Pack Professional 8.12. NOTE: as of 20091105, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

CVE-2009-3877 sun vulnerability CVSS: 5.0 05 Nov 2009, 16:30 UTC

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.

CVE-2009-3876 sun vulnerability CVSS: 5.0 05 Nov 2009, 16:30 UTC

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.

CVE-2009-3875 sun vulnerability CVSS: 5.0 05 Nov 2009, 16:30 UTC

The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.

CVE-2009-3874 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.

CVE-2009-3873 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.

CVE-2009-3872 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.

CVE-2009-3871 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.

CVE-2009-3869 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.

CVE-2009-3868 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.

CVE-2009-3867 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.

CVE-2009-3866 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

CVE-2009-3865 sun vulnerability CVSS: 9.3 05 Nov 2009, 16:30 UTC

The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.

CVE-2009-3864 sun vulnerability CVSS: 7.5 05 Nov 2009, 16:30 UTC

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.

CVE-2009-3851 sun vulnerability CVSS: 7.2 03 Nov 2009, 16:30 UTC

Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command for the XScreenSaver application, which makes it easier for physically proximate attackers to access an unattended workstation for which the intended screen locking did not occur, related to the "restart daemon."

CVE-2009-3839 sun vulnerability CVSS: 6.8 02 Nov 2009, 15:30 UTC

Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10, and OpenSolaris snv_37 through snv_125, might allow remote attackers to execute arbitrary code by leveraging access to the X server.

CVE-2009-3746 sun vulnerability CVSS: 1.9 22 Oct 2009, 16:30 UTC

XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.

CVE-2009-3706 sun vulnerability CVSS: 4.4 16 Oct 2009, 16:30 UTC

Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv_100 through snv_117, allows local users to bypass intended limitations of the file_chown_self privilege via certain uses of the chown system call.

CVE-2009-3692 sun vulnerability CVSS: 7.2 13 Oct 2009, 10:30 UTC

Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via unknown vectors.

CVE-2009-3468 sun vulnerability CVSS: 6.9 29 Sep 2009, 19:30 UTC

Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is enabled, allow local users to execute arbitrary commands or bypass the Mandatory Access Control (MAC) policy via unknown vectors, related to a menu typo and the Style Manager.

CVE-2009-3433 sun vulnerability CVSS: 7.2 28 Sep 2009, 19:30 UTC

Unspecified vulnerability in clsetup in the configuration utility in Sun Solaris Cluster 3.2 allows local users to gain privileges via unknown vectors.

CVE-2009-3432 sun vulnerability CVSS: 1.9 28 Sep 2009, 19:30 UTC

Unspecified vulnerability in xscreensaver in Sun Solaris 10, and OpenSolaris before snv_112, when Xorg or Xnewt is used and RandR is enabled, allows physically proximate attackers to read a locked screen via unknown vectors related to XRandR resize events.

CVE-2009-3390 sun vulnerability CVSS: 7.2 24 Sep 2009, 18:30 UTC

Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris snv_28 through snv_109, allow local users with certain RBAC execution profiles to gain privileges via unknown vectors related to the libima library.

CVE-2009-3183 sun vulnerability CVSS: 7.2 14 Sep 2009, 16:30 UTC

Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows local users to gain privileges via unspecified vectors.

CVE-2009-3164 sun vulnerability CVSS: 7.1 10 Sep 2009, 22:30 UTC

Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix for CVE-2009-2136.

CVE-2009-2139 sun vulnerability CVSS: 9.3 08 Sep 2009, 23:30 UTC

Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238.

CVE-2009-3101 sun vulnerability CVSS: 4.9 08 Sep 2009, 18:30 UTC

xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 10, and OpenSolaris snv_109 through snv_122, does not properly handle Trusted Extensions, which allows local users to cause a denial of service (CPU consumption and console hang) by locking the screen, related to a regression in certain Solaris and OpenSolaris patches.

CVE-2009-3100 sun vulnerability CVSS: 4.0 08 Sep 2009, 18:30 UTC

xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up window, related to a regression in certain Solaris and OpenSolaris patches.

CVE-2009-3000 sun vulnerability CVSS: 7.1 28 Aug 2009, 15:30 UTC

The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handling."

CVE-2009-2972 sun vulnerability CVSS: 7.8 27 Aug 2009, 17:30 UTC

in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."

CVE-2009-2952 sun vulnerability CVSS: 4.9 24 Aug 2009, 15:30 UTC

Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local users to cause a denial of service (panic) via unknown vectors.

CVE-2009-2912 sun vulnerability CVSS: 4.9 21 Aug 2009, 11:02 UTC

The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.

CVE-2009-2856 sun vulnerability CVSS: 3.5 18 Aug 2009, 22:30 UTC

Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.

CVE-2009-2416 sun vulnerability CVSS: 4.3 11 Aug 2009, 18:30 UTC

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

CVE-2009-2705 sun vulnerability CVSS: 4.3 11 Aug 2009, 10:30 UTC

CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.

CVE-2009-2704 sun vulnerability CVSS: 4.3 11 Aug 2009, 10:30 UTC

CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).

CVE-2009-2718 sun vulnerability CVSS: 6.8 10 Aug 2009, 20:30 UTC

The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from the window border to the Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet.

CVE-2009-2690 sun vulnerability CVSS: 5.0 10 Aug 2009, 18:30 UTC

The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.

CVE-2009-2689 sun vulnerability CVSS: 10.0 10 Aug 2009, 18:30 UTC

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

CVE-2009-2476 sun vulnerability CVSS: 10.0 10 Aug 2009, 18:30 UTC

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.

CVE-2009-2475 sun vulnerability CVSS: 7.8 10 Aug 2009, 18:30 UTC

Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.

CVE-2009-2715 sun vulnerability CVSS: 4.9 07 Aug 2009, 19:00 UTC

Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction.

CVE-2009-2714 sun vulnerability CVSS: 4.9 07 Aug 2009, 19:00 UTC

Unspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2 allows guest OS users to cause a denial of service (host OS reboot) via unknown vectors.

CVE-2009-2713 sun vulnerability CVSS: 4.3 07 Aug 2009, 19:00 UTC

The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVE-2009-2712 sun vulnerability CVSS: 2.1 07 Aug 2009, 19:00 UTC

Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by reading debug files.

CVE-2009-2711 sun vulnerability CVSS: 4.9 07 Aug 2009, 19:00 UTC

XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.

CVE-2009-2676 sun vulnerability CVSS: 6.8 05 Aug 2009, 19:30 UTC

Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.

CVE-2009-2675 sun vulnerability CVSS: 10.0 05 Aug 2009, 19:30 UTC

Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.

CVE-2009-2674 sun vulnerability CVSS: 7.5 05 Aug 2009, 19:30 UTC

Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.

CVE-2009-2673 sun vulnerability CVSS: 7.5 05 Aug 2009, 19:30 UTC

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.

CVE-2009-2672 sun vulnerability CVSS: 7.5 05 Aug 2009, 19:30 UTC

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.

CVE-2009-2671 sun vulnerability CVSS: 5.0 05 Aug 2009, 19:30 UTC

The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.

CVE-2009-2670 sun vulnerability CVSS: 5.0 05 Aug 2009, 19:30 UTC

The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.

CVE-2009-2652 sun vulnerability CVSS: 6.8 03 Aug 2009, 14:30 UTC

Unspecified vulnerability in Solaris Trusted Extensions in Sun Solaris 10, and OpenSolaris snv_37 through snv_120, allows remote attackers to cause a denial of service (panic) via vectors involving the parsing of labeled packets.

CVE-2009-2644 sun vulnerability CVSS: 4.9 29 Jul 2009, 17:30 UTC

Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."

CVE-2009-2597 sun vulnerability CVSS: 7.8 27 Jul 2009, 14:30 UTC

The Sun Java System (SJS) Access Manager Policy Agent module 2.2 for SJS Web Proxy Server 4.0 allows remote attackers to cause a denial of service (daemon crash) via a GET request.

CVE-2009-2596 sun vulnerability CVSS: 4.7 27 Jul 2009, 14:30 UTC

Unspecified vulnerability in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to fad_aupath structure members.

CVE-2009-2491 sun vulnerability CVSS: 4.4 16 Jul 2009, 16:30 UTC

The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "resource leaks."

CVE-2009-2490 sun vulnerability CVSS: 1.9 16 Jul 2009, 16:30 UTC

Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to "resource leaks."

CVE-2009-2489 sun vulnerability CVSS: 2.1 16 Jul 2009, 16:30 UTC

Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.

CVE-2009-2488 sun vulnerability CVSS: 4.9 16 Jul 2009, 16:30 UTC

Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving "file operations."

CVE-2009-2487 sun vulnerability CVSS: 7.8 16 Jul 2009, 16:30 UTC

Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.

CVE-2009-2486 sun vulnerability CVSS: 7.8 16 Jul 2009, 16:30 UTC

Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.

CVE-2009-2458 sun vulnerability CVSS: 5.4 14 Jul 2009, 20:30 UTC

Unspecified vulnerability in Sun Fire V215 Server, when using XVR-100 graphic cards on system boards with part number 375-3463 and a hardware dash level -04 or later, allows remote attackers to cause a denial of service (panic) via unknown vectors.

CVE-2009-2445 sun vulnerability CVSS: 5.0 13 Jul 2009, 17:30 UTC

Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI.

CVE-2009-2430 sun vulnerability CVSS: 4.6 10 Jul 2009, 17:30 UTC

Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Auditing is enabled, allows local users with an RBAC execution profile for auditconfig to gain privileges via unknown attack vectors.

CVE-2009-2387 sun vulnerability CVSS: 4.9 09 Jul 2009, 16:30 UTC

Unspecified vulnerability in the proc filesystem in Sun OpenSolaris snv_49 through snv_109 allows local users to cause a denial of service (deadlock and panic) via unknown vectors, related to the ldt_rewrite_syscall function.

CVE-2009-2314 sun vulnerability CVSS: 2.1 05 Jul 2009, 16:30 UTC

Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.

CVE-2009-2297 sun vulnerability CVSS: 7.1 02 Jul 2009, 10:30 UTC

Unspecified vulnerability in the udp subsystem in the kernel in Sun Solaris 10, and OpenSolaris snv_90 through snv_108, when Solaris Trusted Extensions is enabled, allows remote attackers to cause a denial of service (panic) via unspecified vectors involving the crgetlabel function, related to a "TX panic." NOTE: this issue exists because of a regression in earlier kernel patches.

CVE-2009-2296 sun vulnerability CVSS: 10.0 02 Jul 2009, 10:30 UTC

The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create, and modify arbitrary files, via unspecified vectors.

CVE-2009-2283 sun vulnerability CVSS: 4.3 01 Jul 2009, 13:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-2268 sun vulnerability CVSS: 2.6 01 Jul 2009, 13:00 UTC

Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-2187 sun vulnerability CVSS: 4.9 25 Jun 2009, 01:30 UTC

Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allow local users to cause a denial of service (memory consumption) via vectors related to the association of (a) DL_ENABMULTI_REQ and (b) DL_DISABMULTI_REQ messages with ARP messages.

CVE-2009-2137 sun vulnerability CVSS: 7.8 19 Jun 2009, 19:30 UTC

Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-dependent attackers to cause a denial of service (memory consumption) via unspecified vectors related to a large keylen value.

CVE-2009-2136 sun vulnerability CVSS: 7.8 19 Jun 2009, 19:30 UTC

Unspecified vulnerability in the TCP/IP networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_117, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames.

CVE-2009-2135 sun vulnerability CVSS: 4.9 19 Jun 2009, 19:30 UTC

Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.

CVE-2009-1719 sun vulnerability CVSS: 7.5 16 Jun 2009, 23:30 UTC

The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.

CVE-2009-2031 sun vulnerability CVSS: 2.1 11 Jun 2009, 21:30 UTC

smbfs in Sun OpenSolaris snv_84 through snv_110, when default mount permissions are used, allows local users to read arbitrary files, and list arbitrary directories, on CIFS volumes.

CVE-2009-2030 sun vulnerability CVSS: 10.0 11 Jun 2009, 21:30 UTC

Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."

CVE-2009-2029 sun vulnerability CVSS: 5.0 11 Jun 2009, 15:30 UTC

Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.

CVE-2009-2012 sun vulnerability CVSS: 1.9 09 Jun 2009, 17:30 UTC

Unspecified vulnerability in idmap in Sun OpenSolaris snv_88 through snv_110, when a CIFS server is enabled, allows local users to cause a denial of service (idpmapd daemon crash and idmapd outage) via unknown vectors.

CVE-2009-1934 sun vulnerability CVSS: 4.3 05 Jun 2009, 16:00 UTC

Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allows remote attackers to inject arbitrary web script or HTML via the query string in situations that result in a 502 Gateway error.

CVE-2009-1933 sun vulnerability CVSS: 4.7 05 Jun 2009, 16:00 UTC

Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.

CVE-2004-2764 sun vulnerability CVSS: 10.0 02 Jun 2009, 10:30 UTC

Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."

CVE-2004-2763 sun vulnerability CVSS: 5.8 01 Jun 2009, 22:30 UTC

The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

CVE-2003-1573 sun vulnerability CVSS: 10.0 01 Jun 2009, 22:30 UTC

The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."

CVE-2003-1572 sun vulnerability CVSS: 9.3 01 Jun 2009, 22:30 UTC

Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.

CVE-2009-1796 sun vulnerability CVSS: 4.3 26 May 2009, 22:30 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to an error page.

CVE-2008-3870 sun vulnerability CVSS: 10.0 26 May 2009, 21:30 UTC

Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation.

CVE-2008-3869 sun vulnerability CVSS: 10.0 26 May 2009, 21:30 UTC

Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters.

CVE-2009-1763 sun vulnerability CVSS: 7.2 22 May 2009, 16:48 UTC

Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_108 on the x86 platform allows local users to gain privileges or cause a denial of service (filesystem or memory corruption) via unknown vectors.

CVE-2009-1729 sun vulnerability CVSS: 4.3 21 May 2009, 14:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.

CVE-2009-1673 sun vulnerability CVSS: 4.9 18 May 2009, 18:30 UTC

The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.

CVE-2009-1672 sun vulnerability CVSS: 9.3 18 May 2009, 18:30 UTC

The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

CVE-2009-1671 sun vulnerability CVSS: 9.3 18 May 2009, 18:30 UTC

Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.

CVE-2009-1554 sun vulnerability CVSS: 4.3 06 May 2009, 16:30 UTC

Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.

CVE-2009-1478 sun vulnerability CVSS: 4.9 29 Apr 2009, 15:30 UTC

Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.

CVE-2009-1190 sun vulnerability CVSS: 5.0 27 Apr 2009, 22:30 UTC

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

CVE-2009-1357 sun vulnerability CVSS: 6.8 23 Apr 2009, 17:30 UTC

CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.

CVE-2009-1359 sun vulnerability CVSS: 4.9 22 Apr 2009, 15:30 UTC

Unspecified vulnerability in the SCTP sockets implementation in Sun OpenSolaris snv_106 through snv_107 allows local users to cause a denial of service (panic) via unknown vectors.

CVE-2009-1332 sun vulnerability CVSS: 5.0 17 Apr 2009, 14:30 UTC

The Online Help feature in Sun Java System Directory Server 5.2 and Enterprise Edition 5 allows remote attackers to determine the existence of files and directories, and possibly obtain partial contents of files, via unspecified vectors.

CVE-2009-0794 sun vulnerability CVSS: 5.0 13 Apr 2009, 16:30 UTC

Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used in OpenJDK 1.6.0.0 and other products, allows remote attackers to cause a denial of service (applet crash) via a crafted Pulse Audio source data line.

CVE-2009-1276 sun vulnerability CVSS: 2.1 09 Apr 2009, 15:08 UTC

XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.

CVE-2009-0793 sun vulnerability CVSS: 4.3 09 Apr 2009, 15:08 UTC

cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."

CVE-2009-1219 sun vulnerability CVSS: 5.0 01 Apr 2009, 18:30 UTC

Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.

CVE-2009-1218 sun vulnerability CVSS: 4.3 01 Apr 2009, 18:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml.

CVE-2009-1207 sun vulnerability CVSS: 4.4 01 Apr 2009, 10:30 UTC

Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.

CVE-2009-1170 sun vulnerability CVSS: 6.9 30 Mar 2009, 16:30 UTC

Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global zone, to execute arbitrary code in the global zone when a global-zone user is using mdb on a non-global zone process.

CVE-2009-1107 sun vulnerability CVSS: 4.3 25 Mar 2009, 23:30 UTC

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.

CVE-2009-1106 sun vulnerability CVSS: 6.4 25 Mar 2009, 23:30 UTC

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

CVE-2009-1105 sun vulnerability CVSS: 7.5 25 Mar 2009, 23:30 UTC

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.

CVE-2009-1104 sun vulnerability CVSS: 5.8 25 Mar 2009, 23:30 UTC

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.

CVE-2009-1103 sun vulnerability CVSS: 6.4 25 Mar 2009, 23:30 UTC

Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.

CVE-2009-1102 sun vulnerability CVSS: 6.4 25 Mar 2009, 23:30 UTC

Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."

CVE-2009-1101 sun vulnerability CVSS: 5.0 25 Mar 2009, 23:30 UTC

Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."

CVE-2009-1100 sun vulnerability CVSS: 5.0 25 Mar 2009, 23:30 UTC

Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.

CVE-2009-1099 sun vulnerability CVSS: 7.5 25 Mar 2009, 23:30 UTC

Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.

CVE-2009-1098 sun vulnerability CVSS: 9.3 25 Mar 2009, 23:30 UTC

Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.

CVE-2009-1097 sun vulnerability CVSS: 9.3 25 Mar 2009, 23:30 UTC

Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.

CVE-2009-1096 sun vulnerability CVSS: 10.0 25 Mar 2009, 23:30 UTC

Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.

CVE-2009-1095 sun vulnerability CVSS: 10.0 25 Mar 2009, 23:30 UTC

Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.

CVE-2009-1094 sun vulnerability CVSS: 10.0 25 Mar 2009, 23:30 UTC

Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.

CVE-2009-1093 sun vulnerability CVSS: 5.0 25 Mar 2009, 23:30 UTC

LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).

CVE-2009-1084 sun vulnerability CVSS: 6.4 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.

CVE-2009-1083 sun vulnerability CVSS: 9.0 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."

CVE-2009-1082 sun vulnerability CVSS: 9.0 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.

CVE-2009-1081 sun vulnerability CVSS: 4.3 25 Mar 2009, 15:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.

CVE-2009-1080 sun vulnerability CVSS: 4.3 25 Mar 2009, 15:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.

CVE-2009-1079 sun vulnerability CVSS: 4.3 25 Mar 2009, 15:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.

CVE-2009-1078 sun vulnerability CVSS: 4.0 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.

CVE-2009-1077 sun vulnerability CVSS: 6.5 25 Mar 2009, 15:30 UTC

The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.

CVE-2009-1076 sun vulnerability CVSS: 5.0 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

CVE-2009-1075 sun vulnerability CVSS: 5.0 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

CVE-2009-1074 sun vulnerability CVSS: 5.0 25 Mar 2009, 15:30 UTC

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.

CVE-2009-0926 sun vulnerability CVSS: 4.9 17 Mar 2009, 19:30 UTC

Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.

CVE-2009-0925 sun vulnerability CVSS: 4.7 17 Mar 2009, 19:30 UTC

Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through snv_85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6425723.

CVE-2009-0924 sun vulnerability CVSS: 4.7 17 Mar 2009, 19:30 UTC

Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.

CVE-2009-0923 sun vulnerability CVSS: 7.8 17 Mar 2009, 19:30 UTC

Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.

CVE-2009-0913 sun vulnerability CVSS: 4.7 16 Mar 2009, 17:30 UTC

Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.

CVE-2009-0877 sun vulnerability CVSS: 4.3 12 Mar 2009, 15:20 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express allow remote attackers to inject arbitrary web script or HTML via the (1) Full Name or (2) Subject field.

CVE-2009-0876 sun vulnerability CVSS: 6.9 12 Mar 2009, 15:20 UTC

Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.

CVE-2009-0875 sun vulnerability CVSS: 6.9 12 Mar 2009, 15:20 UTC

Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.

CVE-2009-0874 sun vulnerability CVSS: 4.9 12 Mar 2009, 15:20 UTC

Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the door_call function.

CVE-2009-0873 sun vulnerability CVSS: 6.8 11 Mar 2009, 14:19 UTC

The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."

CVE-2009-0872 sun vulnerability CVSS: 6.8 11 Mar 2009, 14:19 UTC

The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.

CVE-2009-0870 sun vulnerability CVSS: 4.7 10 Mar 2009, 20:30 UTC

The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.

CVE-2009-0857 sun vulnerability CVSS: 4.3 09 Mar 2009, 21:30 UTC

Cross-site scripting (XSS) vulnerability in /prm/reports in the Performance Reporting Module (PRM) for Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: this can be leveraged for access to the SunMC Web Console.

CVE-2009-0838 sun vulnerability CVSS: 4.9 06 Mar 2009, 18:30 UTC

The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.

CVE-2008-6192 sun vulnerability CVSS: 4.3 19 Feb 2009, 18:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in unspecified Portlets in Sun Java System Portal Server 7.0 and 7.1 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2009-0609 sun vulnerability CVSS: 7.8 17 Feb 2009, 17:30 UTC

Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests.

CVE-2009-0576 sun vulnerability CVSS: 7.8 13 Feb 2009, 17:30 UTC

Unspecified vulnerability in Sun Java System Directory Server 5.2 p6 and earlier, and Enterprise Edition 5, allows remote attackers to cause a denial of service (daemon crash) via crafted LDAP requests.

CVE-2009-0480 sun vulnerability CVSS: 4.9 09 Feb 2009, 16:30 UTC

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.

CVE-2009-0477 sun vulnerability CVSS: 7.2 08 Feb 2009, 21:30 UTC

Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via vectors related to the contract filesystem.

CVE-2008-6024 sun vulnerability CVSS: 5.4 02 Feb 2009, 22:00 UTC

Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris before snv_37, when automountd is used, allows user-assisted remote attackers to cause a denial of service (unresponsive NFS filesystems) via unknown vectors.

CVE-2009-0348 sun vulnerability CVSS: 5.0 29 Jan 2009, 19:30 UTC

The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

CVE-2009-0346 sun vulnerability CVSS: 4.9 29 Jan 2009, 19:30 UTC

The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.

CVE-2009-0345 sun vulnerability CVSS: 10.0 29 Jan 2009, 19:30 UTC

Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6648082, a different vulnerability than CVE-2007-5717.

CVE-2009-0344 sun vulnerability CVSS: 10.0 29 Jan 2009, 19:30 UTC

Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6633175, a different vulnerability than CVE-2007-5717.

CVE-2009-0319 sun vulnerability CVSS: 6.9 28 Jan 2009, 18:30 UTC

Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."

CVE-2009-0304 sun vulnerability CVSS: 7.8 27 Jan 2009, 20:30 UTC

The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.

CVE-2009-0278 sun vulnerability CVSS: 5.0 27 Jan 2009, 02:30 UTC

Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.

CVE-2009-0277 sun vulnerability CVSS: 7.8 27 Jan 2009, 02:30 UTC

Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors.

CVE-2009-0268 sun vulnerability CVSS: 4.9 26 Jan 2009, 15:30 UTC

Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.

CVE-2009-0267 sun vulnerability CVSS: 5.0 26 Jan 2009, 15:30 UTC

libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.

CVE-2009-0171 sun vulnerability CVSS: 10.0 16 Jan 2009, 21:30 UTC

The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact.

CVE-2009-0170 sun vulnerability CVSS: 6.0 16 Jan 2009, 21:30 UTC

Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.

CVE-2009-0169 sun vulnerability CVSS: 9.0 16 Jan 2009, 21:30 UTC

Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.

CVE-2009-0168 sun vulnerability CVSS: 4.9 16 Jan 2009, 21:30 UTC

Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.

CVE-2009-0167 sun vulnerability CVSS: 4.7 16 Jan 2009, 21:30 UTC

Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."

CVE-2008-5910 sun vulnerability CVSS: 7.2 16 Jan 2009, 21:30 UTC

Unspecified vulnerability in txzonemgr in Sun OpenSolaris has unknown impact and local attack vectors, related to a "Temporary file vulnerability," aka Bug ID 6653462.

CVE-2008-5909 sun vulnerability CVSS: 7.2 16 Jan 2009, 21:30 UTC

Unspecified vulnerability in conv_lpd in Sun OpenSolaris has unknown impact and local attack vectors, related to improper handling of temporary files, aka Bug ID 6655641.

CVE-2008-5908 sun vulnerability CVSS: 7.2 16 Jan 2009, 21:30 UTC

Unspecified vulnerability in the root/boot archive tool in Sun OpenSolaris has unknown impact and local attack vectors, related to a "Temporary file vulnerability," aka Bug ID 6653455.

CVE-2009-0132 sun vulnerability CVSS: 4.9 15 Jan 2009, 17:30 UTC

Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).

CVE-2009-0131 sun vulnerability CVSS: 4.9 15 Jan 2009, 17:30 UTC

The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite, related to an F_ALLOCSP fcntl call.

CVE-2009-0069 sun vulnerability CVSS: 4.9 07 Jan 2009, 20:30 UTC

Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.

CVE-2009-0046 sun vulnerability CVSS: 5.0 07 Jan 2009, 18:30 UTC

Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

CVE-2008-5746 sun vulnerability CVSS: 6.9 29 Dec 2008, 15:24 UTC

Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.

CVE-2008-5699 sun vulnerability CVSS: 4.6 22 Dec 2008, 15:30 UTC

The name service cache daemon (nscd) in Sun Solaris 10 and OpenSolaris snv_50 through snv_104 does not properly check permissions, which allows local users to gain privileges and obtain sensitive information via unspecified vectors.

CVE-2008-5690 sun vulnerability CVSS: 2.1 19 Dec 2008, 17:30 UTC

The Kerberos credential renewal feature in Sun Solaris 8, 9, and 10, and OpenSolaris build snv_01 through snv_104, allows local users to cause a denial of service (authentication failure) via unspecified vectors related to incorrect cache file permissions, and lack of credential storage by the store_cred function in pam_krb5.

CVE-2008-5689 sun vulnerability CVSS: 7.2 19 Dec 2008, 17:30 UTC

tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.

CVE-2008-5685 sun vulnerability CVSS: 10.0 19 Dec 2008, 17:30 UTC

Sun ScApp firmware 5.18.x, 5.19.x, and 5.20.0 through 5.20.10 on Sun Fire and Netra platforms allows remote attackers to access the System Controller (SC), the system console, and possibly the host OS, and cause a denial of service (shutdown or reboot), via spoofed IP packets.

CVE-2008-5684 sun vulnerability CVSS: 5.0 19 Dec 2008, 17:30 UTC

Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).

CVE-2008-5662 sun vulnerability CVSS: 9.3 17 Dec 2008, 20:30 UTC

Multiple buffer overflows in Sun Java Wireless Toolkit (WTK) for CLDC 2.5.2 and earlier allow downloaded programs to execute arbitrary code via unknown vectors.

CVE-2008-5661 sun vulnerability CVSS: 5.4 17 Dec 2008, 20:30 UTC

The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.

CVE-2008-5550 sun vulnerability CVSS: 4.3 12 Dec 2008, 18:30 UTC

Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.

CVE-2008-5549 sun vulnerability CVSS: 5.0 12 Dec 2008, 18:30 UTC

Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local files and read the product's configuration information via unknown vectors related to "access to secure files by ThemeServlet."

CVE-2008-5423 sun vulnerability CVSS: 4.3 11 Dec 2008, 15:30 UTC

Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.

CVE-2008-5422 sun vulnerability CVSS: 7.5 11 Dec 2008, 15:30 UTC

Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors.

CVE-2008-5410 sun vulnerability CVSS: 7.8 10 Dec 2008, 00:30 UTC

The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which allows context-dependent attackers to cause a denial of service (failed cryptographic operations) via unspecified vectors, related to the (1) RSA_sign and (2) RSA_verify functions.

CVE-2008-5360 sun vulnerability CVSS: 6.4 05 Dec 2008, 11:30 UTC

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.

CVE-2008-5359 sun vulnerability CVSS: 9.3 05 Dec 2008, 11:30 UTC

Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.

CVE-2008-5358 sun vulnerability CVSS: 9.3 05 Dec 2008, 11:30 UTC

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.

CVE-2008-5357 sun vulnerability CVSS: 9.3 05 Dec 2008, 11:30 UTC

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

CVE-2008-5356 sun vulnerability CVSS: 9.3 05 Dec 2008, 11:30 UTC

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

CVE-2008-5355 sun vulnerability CVSS: 10.0 05 Dec 2008, 11:30 UTC

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

CVE-2008-5354 sun vulnerability CVSS: 9.3 05 Dec 2008, 11:30 UTC

Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.

CVE-2008-5353 sun vulnerability CVSS: 10.0 05 Dec 2008, 11:30 UTC

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

CVE-2008-5352 sun vulnerability CVSS: 9.3 05 Dec 2008, 11:30 UTC

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.

CVE-2008-5351 sun vulnerability CVSS: 7.5 05 Dec 2008, 11:30 UTC

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.

CVE-2008-5350 sun vulnerability CVSS: 5.0 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.

CVE-2008-5349 sun vulnerability CVSS: 7.1 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.

CVE-2008-5348 sun vulnerability CVSS: 7.1 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.

CVE-2008-5347 sun vulnerability CVSS: 7.5 05 Dec 2008, 11:30 UTC

Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.

CVE-2008-5346 sun vulnerability CVSS: 7.1 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

CVE-2008-5345 sun vulnerability CVSS: 7.5 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.

CVE-2008-5344 sun vulnerability CVSS: 7.5 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.

CVE-2008-5343 sun vulnerability CVSS: 9.0 05 Dec 2008, 11:30 UTC

Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.

CVE-2008-5342 sun vulnerability CVSS: 5.0 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.

CVE-2008-5341 sun vulnerability CVSS: 5.0 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.

CVE-2008-5340 sun vulnerability CVSS: 10.0 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

CVE-2008-5339 sun vulnerability CVSS: 5.0 05 Dec 2008, 11:30 UTC

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.

CVE-2008-2086 sun vulnerability CVSS: 9.3 05 Dec 2008, 02:30 UTC

Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.

CVE-2008-5266 sun vulnerability CVSS: 4.3 28 Nov 2008, 19:00 UTC

Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.

CVE-2008-5133 sun vulnerability CVSS: 5.8 18 Nov 2008, 16:00 UTC

ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queries sent by named.

CVE-2008-5118 sun vulnerability CVSS: 4.3 18 Nov 2008, 00:30 UTC

Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."

CVE-2008-5117 sun vulnerability CVSS: 6.4 18 Nov 2008, 00:30 UTC

Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2008-5116 sun vulnerability CVSS: 7.8 18 Nov 2008, 00:30 UTC

Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.

CVE-2008-5115 sun vulnerability CVSS: 6.8 18 Nov 2008, 00:30 UTC

Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

CVE-2008-5114 sun vulnerability CVSS: 4.3 18 Nov 2008, 00:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2008-5111 sun vulnerability CVSS: 4.7 17 Nov 2008, 23:30 UTC

Unspecified vulnerability in the socket function in Sun Solaris 10 and OpenSolaris snv_57 through snv_91, when InfiniBand hardware is not installed, allows local users to cause a denial of service (panic) via unknown vectors, related to the socksdpv_close function.

CVE-2008-5099 sun vulnerability CVSS: 4.6 17 Nov 2008, 18:18 UTC

Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware's password protection, and gain privileges or obtain data access, via the "ldm ls -l" command, a different vulnerability than CVE-2008-4992.

CVE-2008-5098 sun vulnerability CVSS: 4.3 17 Nov 2008, 18:18 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904.

CVE-2008-5010 sun vulnerability CVSS: 10.0 10 Nov 2008, 15:23 UTC

in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.

CVE-2008-5009 sun vulnerability CVSS: 4.0 10 Nov 2008, 15:23 UTC

Race condition in the s_xout kernel module in Sun Solstice X.25 9.2, when running on a multiple CPU machine, allows local users to cause a denial of service (panic) via vectors involving reading the /dev/xty file.

CVE-2008-4992 sun vulnerability CVSS: 4.6 07 Nov 2008, 19:35 UTC

The SPARC hypervisor in Sun System Firmware 6.6.3 through 6.6.5 and 7.1.3 through 7.1.3.e on UltraSPARC T1, T2, and T2+ processors allows logical domain users to access memory in other logical domains via unknown vectors.

CVE-2008-4910 sun vulnerability CVSS: 10.0 04 Nov 2008, 00:57 UTC

The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.

CVE-2008-4747 sun vulnerability CVSS: 2.1 27 Oct 2008, 20:00 UTC

Unspecified vulnerability in the search feature in Sun Java System LDAP JDK before 4.20 allows context-dependent attackers to obtain sensitive information via unknown attack vectors related to the LDAP JDK library.

CVE-2008-4722 sun vulnerability CVSS: 9.0 23 Oct 2008, 22:00 UTC

Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.

CVE-2008-4619 sun vulnerability CVSS: 10.0 21 Oct 2008, 00:10 UTC

The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. NOTE: this might be a duplicate of CVE-2007-0165.

CVE-2008-4556 sun vulnerability CVSS: 10.0 14 Oct 2008, 22:36 UTC

Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.

CVE-2008-4541 sun vulnerability CVSS: 10.0 13 Oct 2008, 20:00 UTC

Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.7 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.

CVE-2008-4160 sun vulnerability CVSS: 4.7 22 Sep 2008, 18:52 UTC

Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.

CVE-2008-4131 sun vulnerability CVSS: 7.2 19 Sep 2008, 17:15 UTC

Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.

CVE-2008-4117 sun vulnerability CVSS: 7.8 18 Sep 2008, 15:04 UTC

Unspecified vulnerability in a web page in the PRM module in Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVE-2008-3875 sun vulnerability CVSS: 7.2 02 Sep 2008, 14:24 UTC

The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.

CVE-2008-3838 sun vulnerability CVSS: 7.2 27 Aug 2008, 20:41 UTC

Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.

CVE-2008-3839 sun vulnerability CVSS: 4.7 27 Aug 2008, 20:41 UTC

Unspecified vulnerability in the NFS module in the kernel in Sun Solaris 10 and OpenSolaris snv_59 through snv_87, when configured as an NFS server without the nodevices option, allows local users to cause a denial of service (panic) via unspecified vectors.

CVE-2008-3683 sun vulnerability CVSS: 5.0 14 Aug 2008, 20:41 UTC

Unspecified vulnerability in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.5 before SP6 allows remote attackers to cause a denial of service (failure to accept connections) via unknown vectors, probably related to exhaustion of file descriptors.

CVE-2008-3666 sun vulnerability CVSS: 7.1 13 Aug 2008, 17:41 UTC

Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.

CVE-2008-3551 sun vulnerability CVSS: 10.0 08 Aug 2008, 19:41 UTC

Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

CVE-2008-3553 sun vulnerability CVSS: 10.0 08 Aug 2008, 19:41 UTC

Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 3-10." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

CVE-2008-0964 sun vulnerability CVSS: 9.3 08 Aug 2008, 18:41 UTC

Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.

CVE-2008-0965 sun vulnerability CVSS: 9.3 08 Aug 2008, 18:41 UTC

Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.

CVE-2008-3548 sun vulnerability CVSS: 4.9 07 Aug 2008, 21:41 UTC

Unspecified vulnerability in the Sun Netra T5220 Server with firmware 7.1.3 allows local users to cause a denial of service (panic) via unknown vectors.

CVE-2008-3549 sun vulnerability CVSS: 4.7 07 Aug 2008, 21:41 UTC

Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris before snv_90 allows local users to cause a denial of service (system hang or panic) via unknown vectors.

CVE-2008-3450 sun vulnerability CVSS: 7.2 04 Aug 2008, 18:41 UTC

Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.

CVE-2008-3440 sun vulnerability CVSS: 7.5 01 Aug 2008, 14:41 UTC

Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

CVE-2008-3425 sun vulnerability CVSS: 6.5 31 Jul 2008, 22:41 UTC

Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unknown attack vectors.

CVE-2008-3426 sun vulnerability CVSS: 2.1 31 Jul 2008, 22:41 UTC

Unspecified vulnerability in the Solaris Platform Information and Control Library daemon (picld) in Sun Solaris 8 through 10, and OpenSolaris builds snv_01 through snv_95, allows local users to cause a denial of service via unknown vectors that prevent operation of utilities such as prtdiag, prtpicl, and prtfru.

CVE-2008-3107 sun vulnerability CVSS: 10.0 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.

CVE-2008-3108 sun vulnerability CVSS: 10.0 09 Jul 2008, 23:41 UTC

Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.

CVE-2008-3111 sun vulnerability CVSS: 10.0 09 Jul 2008, 23:41 UTC

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

CVE-2008-3112 sun vulnerability CVSS: 10.0 09 Jul 2008, 23:41 UTC

Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.

CVE-2008-3113 sun vulnerability CVSS: 10.0 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.

CVE-2008-3103 sun vulnerability CVSS: 9.3 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to "perform unauthorized operations" via unspecified vectors.

CVE-2008-3105 sun vulnerability CVSS: 8.3 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.

CVE-2008-3109 sun vulnerability CVSS: 7.5 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.

CVE-2008-3115 sun vulnerability CVSS: 7.5 09 Jul 2008, 23:41 UTC

Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which might allow remote attackers to exploit vulnerabilities in these older releases.

CVE-2008-3104 sun vulnerability CVSS: 6.8 09 Jul 2008, 23:41 UTC

Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.

CVE-2008-3114 sun vulnerability CVSS: 5.0 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.

CVE-2008-3106 sun vulnerability CVSS: 4.3 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.

CVE-2008-3110 sun vulnerability CVSS: 4.3 09 Jul 2008, 23:41 UTC

Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.

CVE-2008-2946 sun vulnerability CVSS: 7.8 30 Jun 2008, 22:41 UTC

The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.

CVE-2008-2945 sun vulnerability CVSS: 7.5 30 Jun 2008, 22:41 UTC

Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

CVE-2008-2749 sun vulnerability CVSS: 7.1 18 Jun 2008, 19:41 UTC

Unspecified vulnerability in cshttpd in Sun Java System Calendar Server 6 and 6.3, and Sun ONE Calendar Server 6.0, when access logging (aka service.http.commandlog.all) is enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVE-2008-2751 sun vulnerability CVSS: 4.3 18 Jun 2008, 19:41 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (2) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (3) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, or (4) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc parameter to (a) resourceNode/customResourceNew.jsf; the (5) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (6) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (7) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, (8) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiLookupProp:jndiLookup, or (9) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc parameter to (b) resourceNode/externalResourceNew.jsf; the (10) propertyForm:propertySheet:propertSectionTextField:jndiProp:Jndi, (11) propertyForm:propertySheet:propertSectionTextField:nameProp:name, or (12) propertyForm:propertySheet:propertSectionTextField:descProp:desc parameter to (c) resourceNode/jmsDestinationNew.jsf; the (13) propertyForm:propertySheet:generalPropertySheet:jndiProp:Jndi or (14) propertyForm:propertySheet:generalPropertySheet:descProp:cd parameter to (d) resourceNode/jmsConnectionNew.jsf; the (15) propertyForm:propertySheet:propertSectionTextField:jndiProp:jnditext or (16) propertyForm:propertySheet:propertSectionTextField:descProp:desc parameter to (e) resourceNode/jdbcResourceNew.jsf; the (17) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:nameProp:name, (18) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:classNameProp:classname, or (19) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:loadOrderProp:loadOrder parameter to (f) applications/lifecycleModulesNew.jsf; or the (20) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:jndiProp:name, (21) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:resTypeProp:resType, or (22) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:dbProp:db parameter to (g) resourceNode/jdbcConnectionPoolNew1.jsf.

CVE-2008-2710 sun vulnerability CVSS: 7.2 16 Jun 2008, 20:41 UTC

Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory. NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.

CVE-2008-2708 sun vulnerability CVSS: 4.9 16 Jun 2008, 20:41 UTC

Unspecified vulnerability in the Sun (1) UltraSPARC T2 and (2) UltraSPARC T2+ kernel modules in Sun Solaris 10, and OpenSolaris before snv_93, allows local users to cause a denial of service (panic) via unspecified vectors, probably related to core files.

CVE-2008-2705 sun vulnerability CVSS: 9.3 16 Jun 2008, 18:41 UTC

Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors.

CVE-2008-2706 sun vulnerability CVSS: 4.9 16 Jun 2008, 18:41 UTC

Unspecified vulnerability in the event port implementation in Sun Solaris 10 allows local users to cause a denial of service (panic) by submitting and retrieving user-defined events, probably related to a NULL dereference.

CVE-2008-2552 sun vulnerability CVSS: 4.9 05 Jun 2008, 20:32 UTC

Unspecified vulnerability in the Service Tag Registry on Sun Solaris 10, and Sun Service Tag before 1.1.3, allows local users to cause a denial of service (disk consumption) via unspecified vectors.

CVE-2008-2403 sun vulnerability CVSS: 10.0 04 Jun 2008, 20:32 UTC

Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method.

CVE-2008-2404 sun vulnerability CVSS: 10.0 04 Jun 2008, 20:32 UTC

Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field.

CVE-2008-2401 sun vulnerability CVSS: 7.5 04 Jun 2008, 20:32 UTC

The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications.

CVE-2008-2405 sun vulnerability CVSS: 7.5 04 Jun 2008, 20:32 UTC

Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications.

CVE-2008-2406 sun vulnerability CVSS: 7.5 04 Jun 2008, 20:32 UTC

The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.

CVE-2008-2402 sun vulnerability CVSS: 5.0 04 Jun 2008, 20:32 UTC

The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.

CVE-2008-2539 sun vulnerability CVSS: 7.2 03 Jun 2008, 15:32 UTC

The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified vectors.

CVE-2008-2538 sun vulnerability CVSS: 6.9 03 Jun 2008, 15:32 UTC

Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.

CVE-2008-2518 sun vulnerability CVSS: 4.3 03 Jun 2008, 14:32 UTC

Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the next parameter.

CVE-2008-2418 sun vulnerability CVSS: 4.7 23 May 2008, 15:32 UTC

Race condition in the STREAMS Administrative Driver (sad) in Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

CVE-2008-2166 sun vulnerability CVSS: 4.3 13 May 2008, 20:20 UTC

Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.

CVE-2008-2144 sun vulnerability CVSS: 10.0 12 May 2008, 19:20 UTC

Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.

CVE-2008-2121 sun vulnerability CVSS: 7.8 09 May 2008, 15:20 UTC

The TCP implementation in Sun Solaris 8, 9, and 10 allows remote attackers to cause a denial of service (CPU consumption and new connection timeouts) via a TCP SYN flood attack.

CVE-2008-2120 sun vulnerability CVSS: 5.0 09 May 2008, 15:20 UTC

Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.

CVE-2008-2112 sun vulnerability CVSS: 8.5 08 May 2008, 00:20 UTC

Unspecified vulnerability in Sun Ray Kiosk Mode 4.0 allows local and remote authenticated Sun Ray administrators to gain root privileges via unknown vectors related to utconfig.

CVE-2008-2089 sun vulnerability CVSS: 7.8 06 May 2008, 15:20 UTC

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

CVE-2008-2090 sun vulnerability CVSS: 7.8 06 May 2008, 15:20 UTC

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.

CVE-2008-1995 sun vulnerability CVSS: 7.5 28 Apr 2008, 17:05 UTC

Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect application of policy and allows remote attackers to bypass intended access restrictions for the server.

CVE-2007-5747 sun vulnerability CVSS: 6.8 17 Apr 2008, 19:05 UTC

Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted values that trigger an excessive loop and a stack-based buffer overflow.

CVE-2008-1779 sun vulnerability CVSS: 6.8 14 Apr 2008, 16:05 UTC

Sun Solaris 8, 9, and 10 allows "remote privileged" users to cause a denial of service (panic) via unknown vectors related to self encapsulated IP packets.

CVE-2008-1778 sun vulnerability CVSS: 6.6 14 Apr 2008, 16:05 UTC

Unspecified vulnerability in the floating point context switch implementation in Sun Solaris 9 and 10 on x86 platforms might allow local users to cause a denial of service (application exit), corrupt data, or trigger incorrect calculations via unknown vectors.

CVE-2008-1780 sun vulnerability CVSS: 4.6 14 Apr 2008, 16:05 UTC

Unspecified vulnerability in the labeled networking functionality in Solaris 10 Trusted Extensions allows applications in separate labeling zones to bypass labeling restrictions via unknown vectors.

CVE-2008-1756 sun vulnerability CVSS: 4.9 11 Apr 2008, 21:05 UTC

Unspecified vulnerability in the Qmaster daemon in Sun N1 Grid Engine 6.1 allows local users to cause a denial of service (daemon crash) via unspecified vectors.

CVE-2008-1684 sun vulnerability CVSS: 4.7 06 Apr 2008, 23:44 UTC

inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.

CVE-2008-1480 sun vulnerability CVSS: 4.3 24 Mar 2008, 22:44 UTC

rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.

CVE-2008-1369 sun vulnerability CVSS: 10.0 18 Mar 2008, 17:44 UTC

A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root logins in a manner unintended by the vendor, which allows remote attackers to gain privileges via unspecified vectors.

CVE-2008-1356 sun vulnerability CVSS: 6.3 17 Mar 2008, 17:44 UTC

Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.

CVE-2008-1317 sun vulnerability CVSS: 4.9 13 Mar 2008, 14:44 UTC

Unspecified vulnerability in the Inter-Process Communication (IPC) message queue subsystem in Sun Solaris 10 allows local users to cause a denial of service (reboot) via blocked I/O message queues.

CVE-2008-1286 sun vulnerability CVSS: 7.8 11 Mar 2008, 17:44 UTC

Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.

CVE-2008-1205 sun vulnerability CVSS: 4.9 08 Mar 2008, 00:44 UTC

Unspecified vulnerability in the ipsecah kernel module in Sun Solaris 10, when a key management daemon for IPsec security associations is running, allows local users to cause a denial of service (panic) via unspecified vectors.

CVE-2008-1204 sun vulnerability CVSS: 4.3 08 Mar 2008, 00:44 UTC

Multiple cross-site scripting (XSS) vulnerabilities in the Administration Console in Sun Java System Access Manager 7.1 and 7 2005Q4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) Help and (2) Version windows.

CVE-2008-1185 sun vulnerability CVSS: 9.3 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."

CVE-2008-1186 sun vulnerability CVSS: 9.3 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."

CVE-2008-1188 sun vulnerability CVSS: 9.3 06 Mar 2008, 21:44 UTC

Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."

CVE-2008-1190 sun vulnerability CVSS: 9.3 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.

CVE-2008-1193 sun vulnerability CVSS: 9.3 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application.

CVE-2008-1195 sun vulnerability CVSS: 9.3 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.

CVE-2008-1187 sun vulnerability CVSS: 6.8 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.

CVE-2008-1189 sun vulnerability CVSS: 6.8 06 Mar 2008, 21:44 UTC

Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.

CVE-2008-1191 sun vulnerability CVSS: 6.8 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."

CVE-2008-1192 sun vulnerability CVSS: 6.8 06 Mar 2008, 21:44 UTC

Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and "execute local applications" via unknown vectors.

CVE-2008-1196 sun vulnerability CVSS: 6.8 06 Mar 2008, 21:44 UTC

Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file.

CVE-2008-1194 sun vulnerability CVSS: 4.3 06 Mar 2008, 21:44 UTC

Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.

CVE-2008-1115 sun vulnerability CVSS: 4.9 03 Mar 2008, 18:44 UTC

Unspecified vulnerability in Sun Solaris 8 directory functions allows local users to cause a denial of service (panic) via an unspecified sequence of system calls or commands.

CVE-2008-1095 sun vulnerability CVSS: 6.8 29 Feb 2008, 11:44 UTC

Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.

CVE-2008-0933 sun vulnerability CVSS: 4.7 25 Feb 2008, 18:44 UTC

Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.

CVE-2008-0938 sun vulnerability CVSS: 4.7 25 Feb 2008, 18:44 UTC

Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.

CVE-2008-0836 sun vulnerability CVSS: 4.9 20 Feb 2008, 21:44 UTC

Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectures allows local users to cause a denial of service (panic) via unspecified vectors that trigger a NULL pointer dereference in the vuid3ps2 module, a different issue than CVE-2007-5319.

CVE-2008-0730 sun vulnerability CVSS: 4.6 12 Feb 2008, 21:00 UTC

The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.

CVE-2008-0718 sun vulnerability CVSS: 4.7 12 Feb 2008, 02:00 UTC

Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.

CVE-2008-0657 sun vulnerability CVSS: 10.0 07 Feb 2008, 21:00 UTC

Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.

CVE-2008-0628 sun vulnerability CVSS: 7.8 06 Feb 2008, 21:00 UTC

The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.

CVE-2008-0006 sun vulnerability CVSS: 7.5 18 Jan 2008, 23:00 UTC

Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.

CVE-2008-0269 sun vulnerability CVSS: 4.9 15 Jan 2008, 20:00 UTC

Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.

CVE-2008-0242 sun vulnerability CVSS: 7.2 12 Jan 2008, 02:46 UTC

Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.

CVE-2008-0241 sun vulnerability CVSS: 5.8 11 Jan 2008, 22:46 UTC

Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.

CVE-2008-0239 sun vulnerability CVSS: 4.3 11 Jan 2008, 22:46 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.

CVE-2008-0240 sun vulnerability CVSS: 4.3 11 Jan 2008, 22:46 UTC

/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."

CVE-2007-0012 sun vulnerability CVSS: 4.3 09 Jan 2008, 23:46 UTC

Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.

CVE-2007-6569 sun vulnerability CVSS: 4.3 28 Dec 2007, 21:46 UTC

Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.

CVE-2007-6570 sun vulnerability CVSS: 4.3 28 Dec 2007, 21:46 UTC

Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.

CVE-2007-6571 sun vulnerability CVSS: 4.3 28 Dec 2007, 21:46 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.

CVE-2007-6572 sun vulnerability CVSS: 4.3 28 Dec 2007, 21:46 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.

CVE-2007-6505 sun vulnerability CVSS: 3.5 20 Dec 2007, 23:46 UTC

Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root, which makes it easier for attackers to avoid detection and can make it more difficult to conduct forensics activities.

CVE-2007-6480 sun vulnerability CVSS: 9.4 20 Dec 2007, 20:46 UTC

The Oracle database component in Sun Management Center (Sun MC) 3.6.1, 3.6, and 3.5 Update 1 has a default account, which allows remote attackers to obtain database access and execute arbitrary code.

CVE-2007-6482 sun vulnerability CVSS: 7.8 20 Dec 2007, 20:46 UTC

Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVE-2007-6481 sun vulnerability CVSS: 6.4 20 Dec 2007, 20:46 UTC

Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to create or delete arbitrary directories via unspecified vectors.

CVE-2007-6413 sun vulnerability CVSS: 9.3 17 Dec 2007, 23:46 UTC

Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup restrictions and obtain root access to a filesystem via NFS requests from a client root user.

CVE-2007-6360 sun vulnerability CVSS: 7.8 15 Dec 2007, 01:46 UTC

Unspecified vulnerability in the Sun eXtended System Control Facility (XSCF) Control Package (XCP) firmware before 1050 on SPARC Enterprise M4000, M5000, M8000, and M9000 servers allows remote attackers to cause a denial of service (reboot) via (1) telnet, (2) ssh, or (3) http network traffic that triggers memory exhaustion.

CVE-2007-6225 sun vulnerability CVSS: 4.9 04 Dec 2007, 18:46 UTC

Unspecified vulnerability in Sun Solaris 10, when 64bit mode is used on the x86 platform, allows local users in a Linux (lx) branded zone to cause a denial of service (panic) via unspecified vectors.

CVE-2007-6216 sun vulnerability CVSS: 4.7 04 Dec 2007, 15:46 UTC

Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.

CVE-2007-6180 sun vulnerability CVSS: 7.6 30 Nov 2007, 00:46 UTC

Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via unspecified vectors.

CVE-2007-6059 sun vulnerability CVSS: 5.0 20 Nov 2007, 20:46 UTC

Javamail does not properly handle a series of invalid login attempts in which the same e-mail address is entered as username and password, and the domain portion of this address yields a Java UnknownHostException error, which allows remote attackers to cause a denial of service (connection pool exhaustion) via a large number of requests, resulting in a SQLNestedException. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products.

CVE-2007-3880 sun vulnerability CVSS: 7.2 14 Nov 2007, 01:46 UTC

Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.

CVE-2007-5921 sun vulnerability CVSS: 4.7 10 Nov 2007, 02:46 UTC

Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris 9 and 10 allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2004-1346.

CVE-2007-5717 sun vulnerability CVSS: 10.0 30 Oct 2007, 21:46 UTC

Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) on x86 before firmware 2.70 allows remote attackers to execute arbitrary commands as root on the Service Processor (SP) via unspecified vectors, a different vulnerability than CVE-2007-5170.

CVE-2007-5716 sun vulnerability CVSS: 7.8 30 Oct 2007, 21:46 UTC

Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.

CVE-2007-5726 sun vulnerability CVSS: 6.8 30 Oct 2007, 21:46 UTC

Unspecified vulnerability in the Stream Control Transmission Protocol (sctp) functionality in Sun Solaris 10, when at least one SCTP socket is in the LISTEN state, allows remote attackers to cause a denial of service (panic) via unspecified vectors related to "INIT processing."

CVE-2007-5689 sun vulnerability CVSS: 10.0 29 Oct 2007, 19:46 UTC

The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.

CVE-2007-5632 sun vulnerability CVSS: 4.9 23 Oct 2007, 17:46 UTC

Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions.

CVE-2007-5482 sun vulnerability CVSS: 6.4 16 Oct 2007, 23:17 UTC

Unspecified vulnerability in the FTP service in Sun StorEdge/StorageTek 3510 FC Array with firmware before 4.21 allows remote attackers, with access to the Ethernet management interface, to cause a denial of service (I/O request timeout and device hang) via unspecified vectors.

CVE-2007-5462 sun vulnerability CVSS: 7.8 15 Oct 2007, 22:17 UTC

Unspecified vulnerability in the Sun Solaris RPC services library (librpcsvc) on Solaris 8 through 10 allows remote attackers to cause a denial of service (mountd crash) via unspecified packets to a server that exports many filesystems, and allows local users to cause a denial of service (automountd crash) via unspecified requests to mount filesystems from a server that exports many filesystems.

CVE-2007-5422 sun vulnerability CVSS: 4.9 12 Oct 2007, 21:17 UTC

Unspecified vulnerability in "Solaris Auditing" in the Basic Security Module (BSM) in Sun Solaris 10, when configured for auditing of networking (nt) events, allows local users to cause a denial of service (panic) via unspecified vectors.

CVE-2007-5365 sun vulnerability CVSS: 7.2 11 Oct 2007, 10:17 UTC

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.

CVE-2007-5367 sun vulnerability CVSS: 4.9 11 Oct 2007, 10:17 UTC

Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors.

CVE-2007-5368 sun vulnerability CVSS: 4.9 11 Oct 2007, 10:17 UTC

Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local users to cause a denial of service (multiple application hang) via unspecified vectors.

CVE-2007-5375 sun vulnerability CVSS: 2.6 11 Oct 2007, 10:17 UTC

Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local relative URI, which may be associated with different IP addresses by the browser and the JVM.

CVE-2007-5319 sun vulnerability CVSS: 3.5 09 Oct 2007, 22:17 UTC

Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors.

CVE-2007-5273 sun vulnerability CVSS: 2.6 08 Oct 2007, 23:17 UTC

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.

CVE-2007-5274 sun vulnerability CVSS: 2.6 08 Oct 2007, 23:17 UTC

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.

CVE-2007-5237 sun vulnerability CVSS: 7.1 06 Oct 2007, 00:17 UTC

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local files via an untrusted application, aka "two vulnerabilities."

CVE-2007-5236 sun vulnerability CVSS: 5.4 06 Oct 2007, 00:17 UTC

Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.

CVE-2007-5240 sun vulnerability CVSS: 5.0 06 Oct 2007, 00:17 UTC

Visual truncation vulnerability in the Java Runtime Environment in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier allows remote attackers to circumvent display of the untrusted-code warning banner by creating a window larger than the workstation screen.

CVE-2007-5239 sun vulnerability CVSS: 4.0 06 Oct 2007, 00:17 UTC

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) applets, which allows user-assisted remote attackers to copy or rename arbitrary files when local users perform drag-and-drop operations from the untrusted application or applet window onto certain types of desktop applications.

CVE-2007-5238 sun vulnerability CVSS: 2.6 06 Oct 2007, 00:17 UTC

Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."

CVE-2007-5232 sun vulnerability CVSS: 4.0 05 Oct 2007, 23:17 UTC

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the security model for an applet's outbound connections via a DNS rebinding attack.

CVE-2007-5225 sun vulnerability CVSS: 4.9 05 Oct 2007, 00:17 UTC

Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl.

CVE-2007-5170 sun vulnerability CVSS: 5.0 01 Oct 2007, 20:17 UTC

Unspecified vulnerability in the embedded service processor (SP) before 3.09 in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) allows remote attackers to send arbitrary network traffic and use ELOM as a spam proxy.

CVE-2007-5152 sun vulnerability CVSS: 7.5 01 Oct 2007, 05:17 UTC

Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.

CVE-2007-5153 sun vulnerability CVSS: 6.8 01 Oct 2007, 05:17 UTC

Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2007-5132 sun vulnerability CVSS: 4.9 27 Sep 2007, 19:17 UTC

Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to "the handling of thread contexts."

CVE-2007-5118 sun vulnerability CVSS: 4.7 27 Sep 2007, 17:17 UTC

Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.

CVE-2007-5019 sun vulnerability CVSS: 10.0 20 Sep 2007, 21:17 UTC

Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.

CVE-2007-2834 sun vulnerability CVSS: 9.3 18 Sep 2007, 21:17 UTC

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.

CVE-2007-4732 sun vulnerability CVSS: 4.9 06 Sep 2007, 19:17 UTC

Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.

CVE-2007-4511 sun vulnerability CVSS: 5.0 23 Aug 2007, 19:17 UTC

The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.

CVE-2007-4495 sun vulnerability CVSS: 4.9 23 Aug 2007, 01:17 UTC

Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 20070821 allows local users to cause a denial of service (system panic) via an unspecified ioctl function, aka Bug 6433124.

CVE-2007-4492 sun vulnerability CVSS: 4.9 23 Aug 2007, 00:17 UTC

Multiple unspecified vulnerabilities in the ata disk driver in Sun Solaris 8, 9, and 10 on the x86 platform before 20070821 allow local users to cause a denial of service (system panic) via unspecified ioctl functions, aka Bug 6433123.

CVE-2007-4395 sun vulnerability CVSS: 7.6 17 Aug 2007, 23:17 UTC

Multiple unspecified vulnerabilities in the Role Based Access Control (RBAC) functionality in Sun Solaris 8 allow remote attackers who know the password for a role to gain privileges via that role.

CVE-2007-4381 sun vulnerability CVSS: 9.3 17 Aug 2007, 21:17 UTC

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

CVE-2007-4310 sun vulnerability CVSS: 4.3 13 Aug 2007, 21:17 UTC

The finger daemon (in.fingerd) in Sun Solaris 7 through 9 allows remote attackers to list all accounts that have certain nonstandard GECOS fields via a request composed of a single digit, as demonstrated by a "finger 9@host" command, a different vulnerability than CVE-2001-1503.

CVE-2007-4289 sun vulnerability CVSS: 6.8 09 Aug 2007, 21:17 UTC

Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3715.

CVE-2007-4164 sun vulnerability CVSS: 7.5 07 Aug 2007, 10:17 UTC

CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.

CVE-2007-4126 sun vulnerability CVSS: 1.5 01 Aug 2007, 16:17 UTC

Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.

CVE-2007-4070 sun vulnerability CVSS: 4.9 30 Jul 2007, 17:30 UTC

Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.

CVE-2007-4025 sun vulnerability CVSS: 4.3 26 Jul 2007, 19:30 UTC

Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.

CVE-2007-3922 sun vulnerability CVSS: 6.8 21 Jul 2007, 00:30 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

CVE-2007-3717 sun vulnerability CVSS: 6.9 12 Jul 2007, 16:30 UTC

rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.

CVE-2007-3723 sun vulnerability CVSS: 2.1 12 Jul 2007, 16:30 UTC

The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and performs scheduling based upon CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

CVE-2007-3715 sun vulnerability CVSS: 9.3 11 Jul 2007, 23:30 UTC

Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

CVE-2007-3716 sun vulnerability CVSS: 9.3 11 Jul 2007, 23:30 UTC

The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.

CVE-2007-3700 sun vulnerability CVSS: 1.7 11 Jul 2007, 23:30 UTC

Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.

CVE-2007-3698 sun vulnerability CVSS: 7.8 11 Jul 2007, 22:30 UTC

The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.

CVE-2007-3655 sun vulnerability CVSS: 6.8 10 Jul 2007, 19:30 UTC

Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.

CVE-2007-3504 sun vulnerability CVSS: 9.3 30 Jun 2007, 01:30 UTC

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

CVE-2007-3470 sun vulnerability CVSS: 7.8 28 Jun 2007, 18:30 UTC

Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records.

CVE-2007-3471 sun vulnerability CVSS: 7.2 28 Jun 2007, 18:30 UTC

Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.

CVE-2007-3469 sun vulnerability CVSS: 4.9 28 Jun 2007, 18:30 UTC

Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.

CVE-2007-3458 sun vulnerability CVSS: 4.9 27 Jun 2007, 17:30 UTC

The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Name Service Caching Daemon (nscd) crash) via unspecified vectors.

CVE-2007-3283 sun vulnerability CVSS: 6.8 19 Jun 2007, 22:30 UTC

GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.

CVE-2007-3248 sun vulnerability CVSS: 7.8 18 Jun 2007, 10:30 UTC

Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (system crash) via certain network traffic.

CVE-2007-3223 sun vulnerability CVSS: 7.8 14 Jun 2007, 23:30 UTC

Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.

CVE-2007-3225 sun vulnerability CVSS: 6.4 14 Jun 2007, 23:30 UTC

Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors.

CVE-2007-3224 sun vulnerability CVSS: 5.0 14 Jun 2007, 23:30 UTC

Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors.

CVE-2007-3093 sun vulnerability CVSS: 10.0 06 Jun 2007, 21:30 UTC

Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.

CVE-2007-3094 sun vulnerability CVSS: 9.0 06 Jun 2007, 21:30 UTC

Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to execute arbitrary code via unspecified vectors, related to the WBEM server.

CVE-2007-3069 sun vulnerability CVSS: 4.6 06 Jun 2007, 10:30 UTC

xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.

CVE-2007-2989 sun vulnerability CVSS: 7.8 01 Jun 2007, 10:30 UTC

The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain pointer, which allows remote attackers to cause a denial of service (in.iked daemon crash) by sending certain UDP packets with a source port different from 500. NOTE: this issue might overlap CVE-2006-2298.

CVE-2007-2990 sun vulnerability CVSS: 4.9 01 Jun 2007, 10:30 UTC

Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.

CVE-2007-2906 sun vulnerability CVSS: 5.0 30 May 2007, 10:30 UTC

Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method.

CVE-2007-2904 sun vulnerability CVSS: 4.3 30 May 2007, 10:30 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.

CVE-2007-2882 sun vulnerability CVSS: 5.0 30 May 2007, 01:30 UTC

Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.

CVE-2007-2881 sun vulnerability CVSS: 10.0 29 May 2007, 20:30 UTC

Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.

CVE-2007-2788 sun vulnerability CVSS: 6.8 22 May 2007, 00:30 UTC

Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.

CVE-2007-2789 sun vulnerability CVSS: 4.3 22 May 2007, 00:30 UTC

The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.

CVE-2007-2617 sun vulnerability CVSS: 2.1 11 May 2007, 16:19 UTC

srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.

CVE-2007-2529 sun vulnerability CVSS: 7.2 09 May 2007, 00:19 UTC

Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.

CVE-2007-2466 sun vulnerability CVSS: 7.8 02 May 2007, 22:19 UTC

Unspecified vulnerability in the LDAP Software Development Kit (SDK) for C, as used in Sun Java System Directory Server 5.2 up to Patch 4 and Sun ONE Directory Server 5.1, allows remote attackers to cause a denial of service (crash) via certain BER encodings.

CVE-2007-2465 sun vulnerability CVSS: 4.7 02 May 2007, 22:19 UTC

Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.

CVE-2007-2435 sun vulnerability CVSS: 10.0 02 May 2007, 10:19 UTC

Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.

CVE-2007-2267 sun vulnerability CVSS: 6.8 25 Apr 2007, 20:19 UTC

Unspecified vulnerability in Sun Cluster 3.1 and Solaris Cluster 3.2 before 20070424 allows remote authenticated users, operating from a different cluster node, to cause a denial of service (data corruption or send_mondo panic) via unspecified vectors, as demonstrated by EMC Symcli backup software 6.2.1.

CVE-2007-1681 sun vulnerability CVSS: 7.5 19 Apr 2007, 10:19 UTC

Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.

CVE-2007-2045 sun vulnerability CVSS: 5.0 16 Apr 2007, 22:19 UTC

Unspecified vulnerability in the IP implementation in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (CPU consumption) via crafted IP packets, probably related to fragmented packets with duplicate or missing fragments.

CVE-2006-4175 sun vulnerability CVSS: 7.8 26 Mar 2007, 23:19 UTC

The LDAP server (ns-slapd) in Sun Java System Directory Server 5.2 Patch4 and earlier and ONE Directory Server 5.1 and 5.2 allows remote attackers to cause a denial of service (crash) via malformed queries, probably malformed BER queries, which trigger a free of uninitialized memory locations.

CVE-2007-1526 sun vulnerability CVSS: 6.0 20 Mar 2007, 20:19 UTC

Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors.

CVE-2007-1488 sun vulnerability CVSS: 7.5 16 Mar 2007, 21:19 UTC

Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.

CVE-2007-1419 sun vulnerability CVSS: 4.3 12 Mar 2007, 23:19 UTC

The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.

CVE-2007-1346 sun vulnerability CVSS: 6.6 08 Mar 2007, 22:19 UTC

Unspecified vulnerability in ipmitool for Sun Fire X2100M2 and X2200M2 allows local users to gain privileges and reset or turn off the server.

CVE-2006-7140 sun vulnerability CVSS: 5.8 07 Mar 2007, 20:19 UTC

The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents libike from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.

CVE-2006-7028 sun vulnerability CVSS: 7.8 23 Feb 2007, 03:28 UTC

Single CPU Sun systems running Solaris 7, 8, or 9, such as Netra, allows remote attackers to cause a denial of service (console hang) via a flood of small TCP/IP packets. NOTE: this issue has not been replicated by third parties. In addition, the cause is unknown, although it might be related to "jabber" and generation of a large amount of interrupts within the console, or a hardware error.

CVE-2007-0914 sun vulnerability CVSS: 7.1 14 Feb 2007, 02:28 UTC

Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.

CVE-2007-0895 sun vulnerability CVSS: 2.6 13 Feb 2007, 01:28 UTC

Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.

CVE-2007-0882 sun vulnerability CVSS: 10.0 12 Feb 2007, 20:28 UTC

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

CVE-2007-0668 sun vulnerability CVSS: 6.2 02 Feb 2007, 21:28 UTC

The Loopback Filesystem (LOFS) in Sun Solaris 10 allows local users in a non-global zone to move and rename files in a read-only filesystem, which could lead to a denial of service.

CVE-2007-0634 sun vulnerability CVSS: 7.8 31 Jan 2007, 21:28 UTC

Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.

CVE-2007-0628 sun vulnerability CVSS: 4.3 31 Jan 2007, 18:28 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.

CVE-2007-0503 sun vulnerability CVSS: 6.9 25 Jan 2007, 21:28 UTC

Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.

CVE-2007-0482 sun vulnerability CVSS: 4.6 25 Jan 2007, 00:28 UTC

cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.

CVE-2007-0470 sun vulnerability CVSS: 7.2 24 Jan 2007, 01:28 UTC

Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.

CVE-2007-0393 sun vulnerability CVSS: 4.6 19 Jan 2007, 23:28 UTC

Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and then invoking a setuid program, a variant of CVE-2002-0572.

CVE-2007-0243 sun vulnerability CVSS: 6.8 17 Jan 2007, 22:28 UTC

Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier, and SDK and JRE 1.3.1_18 and earlier allows applets to gain privileges via a GIF image with a block with a 0 width field, which triggers memory corruption.

CVE-2007-0014 sun vulnerability CVSS: 4.4 17 Jan 2007, 00:28 UTC

ChainKey Java Code Protection allows attackers to decompile Java class files via a Java class loader with a modified defineClass method that saves the bytecode to a file before it is passed to the JVM.

CVE-2007-0183 sun vulnerability CVSS: 6.8 12 Jan 2007, 05:04 UTC

Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2007-0165 sun vulnerability CVSS: 7.8 10 Jan 2007, 00:28 UTC

Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.

CVE-2007-0114 sun vulnerability CVSS: 5.0 09 Jan 2007, 00:28 UTC

Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding "content details" via unspecified vectors.

CVE-2006-5870 sun vulnerability CVSS: 9.3 31 Dec 2006, 05:00 UTC

Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer overflows in (1) wmf/winwmf.cxx, during processing of META_ESCAPE records; and wmf/enhwmf.cxx, during processing of (2) EMR_POLYPOLYGON and (3) EMR_POLYPOLYGON16 records.

CVE-2006-6731 sun vulnerability CVSS: 9.3 26 Dec 2006, 23:28 UTC

Multiple buffer overflows in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allow attackers to develop Java applets that read, write, or execute local files, possibly related to (1) integer overflows in the Java_sun_awt_image_ImagingLib_convolveBI, awt_parseRaster, and awt_parseColorModel functions; (2) a stack overflow in the Java_sun_awt_image_ImagingLib_lookupByteRaster function; and (3) improper handling of certain negative values in the Java_sun_font_SunLayoutEngine_nativeLayout function. NOTE: some of these details are obtained from third party information.

CVE-2006-6745 sun vulnerability CVSS: 9.3 26 Dec 2006, 23:28 UTC

Multiple unspecified vulnerabilities in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 7 and earlier, and Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, allow attackers to develop Java applets or applications that are able to gain privileges, related to serialization in JRE.

CVE-2006-6736 sun vulnerability CVSS: 4.3 26 Dec 2006, 23:28 UTC

Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 6 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_12 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The second issue."

CVE-2006-6737 sun vulnerability CVSS: 4.3 26 Dec 2006, 23:28 UTC

Unspecified vulnerability in Sun Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 5 and earlier, Java System Development Kit (SDK) and JRE 1.4.2_10 and earlier 1.4.x versions, and SDK and JRE 1.3.1_18 and earlier allows attackers to use untrusted applets to "access data in other applets," aka "The first issue."

CVE-2006-6494 sun vulnerability CVSS: 6.6 13 Dec 2006, 01:28 UTC

Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.

CVE-2006-6495 sun vulnerability CVSS: 6.6 13 Dec 2006, 01:28 UTC

Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function. NOTE: this issue normally does not cross privilege boundaries, except in cases of external introduction of malicious message files, or if it is leveraged with other vulnerabilities such as CVE-2006-6494.

CVE-2006-6276 sun vulnerability CVSS: 6.8 04 Dec 2006, 11:28 UTC

HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.

CVE-2006-6275 sun vulnerability CVSS: 4.7 04 Dec 2006, 11:28 UTC

Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function and SIGKILL and /proc PCAGENT signals.

CVE-2006-6009 sun vulnerability CVSS: 5.0 21 Nov 2006, 23:07 UTC

Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted applet accessing data in other applets.

CVE-2006-5726 sun vulnerability CVSS: 4.9 06 Nov 2006, 17:07 UTC

alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.

CVE-2006-5652 sun vulnerability CVSS: 4.3 03 Nov 2006, 00:07 UTC

Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.

CVE-2006-5653 sun vulnerability CVSS: 4.3 03 Nov 2006, 00:07 UTC

Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.

CVE-2006-5654 sun vulnerability CVSS: 4.0 03 Nov 2006, 00:07 UTC

Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.

CVE-2006-5486 sun vulnerability CVSS: 4.3 24 Oct 2006, 22:07 UTC

Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.

CVE-2006-5396 sun vulnerability CVSS: 4.9 18 Oct 2006, 19:07 UTC

The tcp_fuse_rcv_drain function in the Sun Solaris 10 kernel before 20061017, when TCP Fusion is enabled, allows local users to cause a denial of service (system crash) via a TCP loopback connection with both endpoints on the same system.

CVE-2006-4842 sun vulnerability CVSS: 3.6 12 Oct 2006, 00:07 UTC

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

CVE-2006-5201 sun vulnerability CVSS: 4.0 10 Oct 2006, 04:06 UTC

Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.

CVE-2006-5213 sun vulnerability CVSS: 3.6 10 Oct 2006, 04:06 UTC

Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).

CVE-2006-5215 sun vulnerability CVSS: 2.6 10 Oct 2006, 04:06 UTC

The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.

CVE-2006-5214 sun vulnerability CVSS: 1.2 10 Oct 2006, 04:06 UTC

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.

CVE-2006-5073 sun vulnerability CVSS: 7.8 29 Sep 2006, 00:07 UTC

Unspecified vulnerability in Sun Solaris 8, 9 and 10 allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets, a different vulnerability than CVE-2006-5013.

CVE-2006-5075 sun vulnerability CVSS: 7.8 29 Sep 2006, 00:07 UTC

The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client.

CVE-2006-5013 sun vulnerability CVSS: 7.8 27 Sep 2006, 01:07 UTC

Sun Solaris 10 before patch 118855-16 (20060925), when run on x64 systems using IPv6, allows remote attackers to cause a denial of service (kernel panic) via crafted IPv6 packets.

CVE-2006-5012 sun vulnerability CVSS: 6.6 27 Sep 2006, 01:07 UTC

Unspecified vulnerability in Sun Solaris 8, 9, and 10 before 20060925 allows local users to cause a denial of service (disable syslog) and prevent security messages from being logged via unspecified vectors.

CVE-2006-4958 sun vulnerability CVSS: 6.8 23 Sep 2006, 10:07 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available.

CVE-2006-4959 sun vulnerability CVSS: 5.0 23 Sep 2006, 10:07 UTC

Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, including hostnames, versions, and settings details, via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available.

CVE-2006-4773 sun vulnerability CVSS: 5.0 14 Sep 2006, 00:07 UTC

Sun StorEdge 6130 Array Controllers with firmware 06.12.10.11 and earlier allow remote attackers to cause a denial of service (controller reboot) via a flood of traffic on the LAN.

CVE-2006-4655 sun vulnerability CVSS: 4.6 09 Sep 2006, 00:04 UTC

Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.

CVE-2006-4439 sun vulnerability CVSS: 3.6 29 Aug 2006, 23:04 UTC

pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.

CVE-2006-4353 sun vulnerability CVSS: 5.0 25 Aug 2006, 10:04 UTC

Unspecified vulnerability in Sun Java System Content Delivery Server 4.0, 4.1, and 5.0 allows local and remote attackers to read data from arbitrary files via unspecified vectors.

CVE-2006-4319 sun vulnerability CVSS: 7.2 24 Aug 2006, 01:04 UTC

Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307.

CVE-2006-4306 sun vulnerability CVSS: 7.2 23 Aug 2006, 19:04 UTC

Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 allows local users to execute arbitrary commands via unspecified vectors, involving the default Role-Based Access Control (RBAC) settings in the "File System Management" profile.

CVE-2006-4307 sun vulnerability CVSS: 7.2 23 Aug 2006, 19:04 UTC

Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.

CVE-2006-4302 sun vulnerability CVSS: 5.0 23 Aug 2006, 01:04 UTC

The Java Plug-in J2SE 1.3.0_02 through 5.0 Update 5, and Java Web Start 1.0 through 1.2 and J2SE 1.4.2 through 5.0 Update 5, allows remote attackers to exploit vulnerabilities by specifying a JRE version that contain vulnerabilities.

CVE-2006-4303 sun vulnerability CVSS: 2.6 23 Aug 2006, 01:04 UTC

Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun Solaris 10 allows remote attackers to cause a denial of service ("tight loop" and CPU consumption for listener applications) via unknown vectors related to TCP fusion (do_tcp_fusion).

CVE-2006-4139 sun vulnerability CVSS: 5.4 14 Aug 2006, 23:04 UTC

Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via unspecified vectors related to ifconfig and either netstat or SNMP queries.

CVE-2006-4117 sun vulnerability CVSS: 5.4 14 Aug 2006, 21:04 UTC

The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a large number of TCP connections ("heavy TCP/IP loads"). NOTE: the original report specifies the function name as "drain_squeue," but this is likely incorrect.

CVE-2006-4049 sun vulnerability CVSS: 2.1 09 Aug 2006, 23:04 UTC

Unspecified vulnerability in the utxconfig utility in Sun Ray Server Software 3.x allows local users to create or overwrite arbitrary files via unknown attack vectors.

CVE-2006-3968 sun vulnerability CVSS: 5.0 01 Aug 2006, 22:04 UTC

The crypto provider in Sun Solaris 10 3/05 HW2 without patch 121236-01, when running on Sun Fire T2000 platforms, incorrectly verifies a DSA signature, which might prevent applications from detecting that the data has been modified.

CVE-2006-3941 sun vulnerability CVSS: 7.5 31 Jul 2006, 23:04 UTC

Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate.

CVE-2006-3921 sun vulnerability CVSS: 4.0 28 Jul 2006, 23:04 UTC

Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.

CVE-2006-3920 sun vulnerability CVSS: 5.0 28 Jul 2006, 22:04 UTC

The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause a denial of service (resource exhaustion) via a TCP packet with an incorrect sequence number, which triggers an ACK storm.

CVE-2006-3824 sun vulnerability CVSS: 4.9 25 Jul 2006, 13:22 UTC

systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.

CVE-2006-3825 sun vulnerability CVSS: 2.1 25 Jul 2006, 13:22 UTC

The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication.

CVE-2006-3781 sun vulnerability CVSS: 7.8 24 Jul 2006, 12:19 UTC

Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via unspecified vectors involving the event port API.

CVE-2006-3782 sun vulnerability CVSS: 4.9 24 Jul 2006, 12:19 UTC

Unspecified vulnerability in the kernel debugger (kmdb) in Sun Solaris 10, when running on x86, allows local users to cause a denial of service (system hang) via unspecified vectors.

CVE-2006-3783 sun vulnerability CVSS: 4.9 24 Jul 2006, 12:19 UTC

Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors involving (1) the /net mount point and (2) the "-hosts" map in a mount point.

CVE-2006-3728 sun vulnerability CVSS: 6.8 21 Jul 2006, 14:03 UTC

Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption."

CVE-2006-3664 sun vulnerability CVSS: 5.0 18 Jul 2006, 15:47 UTC

Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.

CVE-2006-3606 sun vulnerability CVSS: 5.0 18 Jul 2006, 15:46 UTC

Unspecified vulnerability in Sun Solaris X Inter Client Exchange library (libICE) on Solaris 8 and 9 allows context-dependent attackers to cause a denial of service (application crash) to applications that use the library.

CVE-2006-2198 sun vulnerability CVSS: 7.6 30 Jun 2006, 18:05 UTC

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

CVE-2006-2199 sun vulnerability CVSS: 7.6 30 Jun 2006, 18:05 UTC

Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.

CVE-2006-3117 sun vulnerability CVSS: 7.6 30 Jun 2006, 18:05 UTC

Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to execute arbitrary code via a crafted OpenOffice XML document that is not properly handled by (1) Calc, (2) Draw, (3) Impress, (4) Math, or (5) Writer, aka "File Format / Buffer Overflow Vulnerability."

CVE-2006-3225 sun vulnerability CVSS: 2.6 26 Jun 2006, 16:05 UTC

Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.

CVE-2006-3159 sun vulnerability CVSS: 2.1 22 Jun 2006, 22:06 UTC

pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.

CVE-2006-3127 sun vulnerability CVSS: 7.8 21 Jun 2006, 23:02 UTC

Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations.

CVE-2006-2930 sun vulnerability CVSS: 4.6 09 Jun 2006, 10:02 UTC

Unspecified vulnerability in Sun Grid Engine 5.3 and Sun N1 Grid Engine 6.0, when configured in Certificate Security Protocol (CSP) Mode, allows local users to shut down the grid service or gain access, even if access is denied.

CVE-2006-2790 sun vulnerability CVSS: 7.2 02 Jun 2006, 22:02 UTC

A package component in Sun Storage Automated Diagnostic Environment (StorADE) 2.4 uses world-writable permissions for certain critical files and directories, which allows local users to gain privileges.

CVE-2006-2614 sun vulnerability CVSS: 4.6 26 May 2006, 01:06 UTC

Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (1) /cr/hd_jobs_db.sh, (2) /cr/hd_plan_checkin.sh, and (3) /cr/oracle_plan_checkin.sh, which allows local users to obtain System Manager passwords.

CVE-2006-2513 sun vulnerability CVSS: 7.5 22 May 2006, 21:06 UTC

Unspecified vulnerability in the installation process in Sun Java System Directory Server 5.2 causes wrong user data to be written to a file created by the installation, which allows remote attackers or local users to gain privileges.

CVE-2006-2501 sun vulnerability CVSS: 6.8 20 May 2006, 03:02 UTC

Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving error messages.

CVE-2006-2426 sun vulnerability CVSS: 6.4 17 May 2006, 10:06 UTC

Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.

CVE-2006-2064 sun vulnerability CVSS: 4.6 27 Apr 2006, 13:34 UTC

Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain privileges or cause a denial of service (application failure) via unknown attack vectors that involve the getpwnam family of non-reentrant functions.

CVE-2006-1830 sun vulnerability CVSS: 3.7 19 Apr 2006, 16:06 UTC

Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.

CVE-2006-1780 sun vulnerability CVSS: 2.1 13 Apr 2006, 10:02 UTC

The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.

CVE-2006-1782 sun vulnerability CVSS: 2.1 13 Apr 2006, 10:02 UTC

Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.

CVE-2006-1601 sun vulnerability CVSS: 1.7 04 Apr 2006, 10:04 UTC

Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors.

CVE-2006-1506 sun vulnerability CVSS: 7.2 30 Mar 2006, 01:06 UTC

Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.

CVE-2006-0745 sun vulnerability CVSS: 7.2 21 Mar 2006, 02:06 UTC

X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.

CVE-2006-1092 sun vulnerability CVSS: 2.1 09 Mar 2006, 13:06 UTC

Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to allocate a large amount of system memory that does not get freed.

CVE-2006-0901 sun vulnerability CVSS: 7.2 27 Feb 2006, 19:06 UTC

Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.

CVE-2006-0769 sun vulnerability CVSS: 7.2 18 Feb 2006, 21:02 UTC

Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.

CVE-2006-0647 sun vulnerability CVSS: 5.0 13 Feb 2006, 11:06 UTC

LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.

CVE-2006-0614 sun vulnerability CVSS: 6.4 09 Feb 2006, 02:02 UTC

Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "first issue."

CVE-2006-0615 sun vulnerability CVSS: 4.0 09 Feb 2006, 02:02 UTC

Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third issues."

CVE-2006-0616 sun vulnerability CVSS: 4.0 09 Feb 2006, 02:02 UTC

Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."

CVE-2006-0617 sun vulnerability CVSS: 4.0 09 Feb 2006, 02:02 UTC

Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fifth, sixth, and seventh issues."

CVE-2006-0531 sun vulnerability CVSS: 7.2 04 Feb 2006, 00:06 UTC

Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.

CVE-2006-0516 sun vulnerability CVSS: 2.1 02 Feb 2006, 11:02 UTC

Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.

CVE-2006-0408 sun vulnerability CVSS: 7.2 25 Jan 2006, 02:03 UTC

rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.

CVE-2006-0227 sun vulnerability CVSS: 2.6 17 Jan 2006, 20:07 UTC

Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.

CVE-2006-0190 sun vulnerability CVSS: 7.2 13 Jan 2006, 11:03 UTC

Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.

CVE-2006-0191 sun vulnerability CVSS: 4.9 13 Jan 2006, 11:03 UTC

Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.

CVE-2006-0161 sun vulnerability CVSS: 4.6 10 Jan 2006, 19:03 UTC

Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.

CVE-2005-2529 sun vulnerability CVSS: 10.0 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives."

CVE-2005-2530 sun vulnerability CVSS: 10.0 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to "Mac OS X specific extensions."

CVE-2005-4795 sun vulnerability CVSS: 7.2 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.

CVE-2005-1753 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

CVE-2005-1754 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products.

CVE-2005-2738 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program.

CVE-2005-4797 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to delete arbitrary files via ".." sequences in an "Unlink data file" command.

CVE-2005-4804 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications.

CVE-2005-4805 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update 2 and earlier, allows remote attackers to obtain the source code for Java Server pages (JSP) via unknown vectors.

CVE-2005-4806 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.

CVE-2005-4845 sun vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.

CVE-2005-4796 sun vulnerability CVSS: 3.6 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in the XView library (libxview.so) in Solaris 2.5 to 10 allows local users to corrupt files via unknown vectors related to the handling of the clipboard selection while an XView application exits.

CVE-2005-4701 sun vulnerability CVSS: 2.1 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in Process File System (procfs) in Sun Solaris 10 allows local users to obtain sensitive information such as process working directories via unknown attack vectors, possibly pwdx.

CVE-2005-4706 sun vulnerability CVSS: 2.1 31 Dec 2005, 05:00 UTC

Unspecified vulnerability in the "privilege management" feature of Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors that trigger a null dereference in the secpolicy_fs_common function.

CVE-2005-4552 sun vulnerability CVSS: 7.2 28 Dec 2005, 11:03 UTC

The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.

CVE-2005-4350 sun vulnerability CVSS: 7.8 20 Dec 2005, 00:03 UTC

Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 and A.02.x before A.02.00.08 on HP-UX B.11.00 through B.11.23 allows remote attackers to cause an unspecified denial of service via unknown attack vectors.

CVE-2005-4133 sun vulnerability CVSS: 2.1 09 Dec 2005, 15:03 UTC

Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files.

CVE-2005-4045 sun vulnerability CVSS: 7.5 07 Dec 2005, 11:03 UTC

Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif.

CVE-2005-4046 sun vulnerability CVSS: 4.0 07 Dec 2005, 11:03 UTC

Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers to conduct man-in-the-middle (MITM) attacks and "compromise data privacy."

CVE-2005-3904 sun vulnerability CVSS: 7.5 30 Nov 2005, 11:03 UTC

Unspecified vulnerability in Java Management Extensions (JMX) in Java JDK and JRE 5.0 Update 3, 1.4.2 and later, 1.3.1 and later allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors.

CVE-2005-3905 sun vulnerability CVSS: 7.5 30 Nov 2005, 11:03 UTC

Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with the "first issue" identified in SUNALERT:102003.

CVE-2005-3906 sun vulnerability CVSS: 7.5 30 Nov 2005, 11:03 UTC

Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors, a different set of vulnerabilities than CVE-2005-3905. NOTE: this is associated with the "second and third issues" identified in SUNALERT:102003.

CVE-2005-3907 sun vulnerability CVSS: 7.5 30 Nov 2005, 11:03 UTC

Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrusted Java applets.

CVE-2005-3781 sun vulnerability CVSS: 5.0 23 Nov 2005, 02:03 UTC

Unspecified vulnerability in in.named in Solaris 9 allows attackers to cause a denial of service via unknown manipulations that cause in.named to "make unnecessary queries."

CVE-2005-3674 sun vulnerability CVSS: 7.8 18 Nov 2005, 21:03 UTC

The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked crash) via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVE-2005-3583 sun vulnerability CVSS: 7.8 16 Nov 2005, 07:42 UTC

(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss.

CVE-2005-3472 sun vulnerability CVSS: 5.0 03 Nov 2005, 02:02 UTC

Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.

CVE-2005-3398 sun vulnerability CVSS: 4.3 01 Nov 2005, 12:47 UTC

The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.

CVE-2005-3269 sun vulnerability CVSS: 7.5 20 Oct 2005, 23:02 UTC

Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges.

CVE-2005-3250 sun vulnerability CVSS: 2.1 17 Oct 2005, 20:06 UTC

Unknown vulnerability in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors related to the "/proc" filesystem, which trigger a null dereference.

CVE-2005-3099 sun vulnerability CVSS: 4.6 28 Sep 2005, 23:03 UTC

Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.

CVE-2005-3071 sun vulnerability CVSS: 2.1 27 Sep 2005, 19:03 UTC

Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.

CVE-2005-3001 sun vulnerability CVSS: 2.1 20 Sep 2005, 23:03 UTC

Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

CVE-2005-2870 sun vulnerability CVSS: 7.5 08 Sep 2005, 23:03 UTC

Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.

CVE-2005-0357 sun vulnerability CVSS: 7.5 23 Aug 2005, 04:00 UTC

EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.

CVE-2005-0358 sun vulnerability CVSS: 7.5 23 Aug 2005, 04:00 UTC

EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.

CVE-2005-0359 sun vulnerability CVSS: 6.4 23 Aug 2005, 04:00 UTC

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.

CVE-2005-2094 sun vulnerability CVSS: 4.3 05 Jul 2005, 04:00 UTC

Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

CVE-2005-2072 sun vulnerability CVSS: 7.2 29 Jun 2005, 04:00 UTC

The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.

CVE-2005-2071 sun vulnerability CVSS: 4.6 29 Jun 2005, 04:00 UTC

traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).

CVE-2005-2022 sun vulnerability CVSS: 4.3 17 Jun 2005, 04:00 UTC

Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.

CVE-2005-1973 sun vulnerability CVSS: 5.1 16 Jun 2005, 04:00 UTC

Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.

CVE-2005-1974 sun vulnerability CVSS: 5.1 16 Jun 2005, 04:00 UTC

Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.

CVE-2005-2032 sun vulnerability CVSS: 2.1 16 Jun 2005, 04:00 UTC

Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.

CVE-2005-0488 sun vulnerability CVSS: 5.0 14 Jun 2005, 04:00 UTC

Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

CVE-2005-1887 sun vulnerability CVSS: 4.6 09 Jun 2005, 04:00 UTC

Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.

CVE-2005-1889 sun vulnerability CVSS: 5.0 07 Jun 2005, 04:00 UTC

Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.

CVE-2005-1609 sun vulnerability CVSS: 7.5 16 May 2005, 04:00 UTC

Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data.

CVE-2005-1591 sun vulnerability CVSS: 5.0 16 May 2005, 04:00 UTC

Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.

CVE-2005-1518 sun vulnerability CVSS: 2.1 11 May 2005, 04:00 UTC

Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.

CVE-2005-0836 sun vulnerability CVSS: 10.0 02 May 2005, 04:00 UTC

Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.

CVE-2005-0248 sun vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.

CVE-2005-0418 sun vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.

CVE-2005-1232 sun vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.

CVE-2005-0816 sun vulnerability CVSS: 7.2 02 May 2005, 04:00 UTC

Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.

CVE-2005-0223 sun vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

The Software Development Kit (SDK) and Run Time Environment (RTE) 1.4.1 and 1.4.2 for Tru64 UNIX allows remote attackers to cause a denial of service (Java Virtual Machine hang) via object deserialization.

CVE-2005-0426 sun vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.

CVE-2005-1080 sun vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.

CVE-2005-1105 sun vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.

CVE-2005-1150 sun vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).

CVE-2005-1124 sun vulnerability CVSS: 4.6 02 May 2005, 04:00 UTC

Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.

CVE-2005-0549 sun vulnerability CVSS: 4.3 02 May 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.

CVE-2005-0742 sun vulnerability CVSS: 4.3 02 May 2005, 04:00 UTC

Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2005-0576 sun vulnerability CVSS: 3.6 02 May 2005, 04:00 UTC

Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.

CVE-2004-0790 sun vulnerability CVSS: 5.0 12 Apr 2005, 04:00 UTC

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

CVE-2004-0791 sun vulnerability CVSS: 5.0 12 Apr 2005, 04:00 UTC

Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

CVE-2005-0471 sun vulnerability CVSS: 5.0 14 Mar 2005, 05:00 UTC

Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.

CVE-2005-0548 sun vulnerability CVSS: 4.3 07 Mar 2005, 05:00 UTC

Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.

CVE-2005-0109 sun vulnerability CVSS: 4.7 05 Mar 2005, 05:00 UTC

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

CVE-2004-1029 sun vulnerability CVSS: 9.3 01 Mar 2005, 05:00 UTC

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

CVE-2004-0481 sun vulnerability CVSS: 2.1 23 Feb 2005, 05:00 UTC

The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.

CVE-2005-0447 sun vulnerability CVSS: 5.0 15 Feb 2005, 05:00 UTC

Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.

CVE-2004-1170 sun vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

CVE-2004-0817 sun vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2004-0826 sun vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.

CVE-2004-2393 sun vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

CVE-2004-2758 sun vulnerability CVSS: 7.5 31 Dec 2004, 05:00 UTC

Multiple unspecified vulnerabilities in the H.323 protocol implementation for Sun SunForum 3.2 and 3D 1.0 allow remote attackers to cause a denial of service (segmentation fault and process crash), as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

CVE-2004-0780 sun vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.

CVE-2004-1767 sun vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.

CVE-2004-2686 sun vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.

CVE-2004-0802 sun vulnerability CVSS: 5.1 31 Dec 2004, 05:00 UTC

Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.

CVE-2004-1393 sun vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).

CVE-2004-1503 sun vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.

CVE-2004-2216 sun vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate.

CVE-2004-2540 sun vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.

CVE-2004-2641 sun vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.

CVE-2004-1394 sun vulnerability CVSS: 4.6 31 Dec 2004, 05:00 UTC

The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.

CVE-2004-2306 sun vulnerability CVSS: 4.6 31 Dec 2004, 05:00 UTC

Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection.

CVE-2004-2759 sun vulnerability CVSS: 2.1 31 Dec 2004, 05:00 UTC

Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.

CVE-2004-1307 sun vulnerability CVSS: 7.5 21 Dec 2004, 05:00 UTC

Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.

CVE-2004-1351 sun vulnerability CVSS: 10.0 07 Dec 2004, 05:00 UTC

Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.

CVE-2004-0496 sun vulnerability CVSS: 7.2 06 Dec 2004, 05:00 UTC

Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.

CVE-2004-1352 sun vulnerability CVSS: 7.2 01 Dec 2004, 05:00 UTC

Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.

CVE-2004-0360 sun vulnerability CVSS: 7.2 23 Nov 2004, 05:00 UTC

Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.

CVE-2004-0079 sun vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVE-2004-0081 sun vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

CVE-2004-0112 sun vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVE-2004-1350 sun vulnerability CVSS: 7.5 30 Oct 2004, 04:00 UTC

Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.

CVE-2004-1353 sun vulnerability CVSS: 7.2 19 Oct 2004, 04:00 UTC

Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.

CVE-2004-0801 sun vulnerability CVSS: 7.5 16 Sep 2004, 04:00 UTC

Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.

CVE-2004-0827 sun vulnerability CVSS: 7.5 16 Sep 2004, 04:00 UTC

Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.

CVE-2004-1348 sun vulnerability CVSS: 5.0 06 Sep 2004, 04:00 UTC

Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).

CVE-2004-0800 sun vulnerability CVSS: 4.6 24 Aug 2004, 04:00 UTC

Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.

CVE-2004-0523 sun vulnerability CVSS: 10.0 18 Aug 2004, 04:00 UTC

Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.

CVE-2004-0651 sun vulnerability CVSS: 5.0 06 Aug 2004, 04:00 UTC

Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).

CVE-2004-0653 sun vulnerability CVSS: 2.1 06 Aug 2004, 04:00 UTC

Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.

CVE-2004-0654 sun vulnerability CVSS: 2.1 06 Aug 2004, 04:00 UTC

Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).

CVE-2004-0742 sun vulnerability CVSS: 10.0 27 Jul 2004, 04:00 UTC

Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view.

CVE-2004-0701 sun vulnerability CVSS: 4.6 27 Jul 2004, 04:00 UTC

Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.

CVE-2004-1345 sun vulnerability CVSS: 7.2 21 Jun 2004, 04:00 UTC

Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access.

CVE-2004-1346 sun vulnerability CVSS: 2.1 19 Jun 2004, 04:00 UTC

The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.

CVE-2004-1354 sun vulnerability CVSS: 5.0 14 May 2004, 04:00 UTC

The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.

CVE-2004-1355 sun vulnerability CVSS: 2.1 26 Apr 2004, 04:00 UTC

Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

CVE-2004-1356 sun vulnerability CVSS: 2.1 23 Apr 2004, 04:00 UTC

Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

CVE-2004-1942 sun vulnerability CVSS: 7.5 19 Apr 2004, 04:00 UTC

The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.

CVE-2004-1357 sun vulnerability CVSS: 5.0 07 Apr 2004, 04:00 UTC

The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.

CVE-2004-1815 sun vulnerability CVSS: 5.0 15 Mar 2004, 05:00 UTC

Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).

CVE-2004-1358 sun vulnerability CVSS: 5.0 12 Mar 2004, 05:00 UTC

The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.

CVE-2004-1359 sun vulnerability CVSS: 4.6 04 Mar 2004, 05:00 UTC

Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.

CVE-2004-1180 sun vulnerability CVSS: 5.0 16 Feb 2004, 05:00 UTC

Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).

CVE-2004-1082 sun vulnerability CVSS: 7.5 03 Feb 2004, 05:00 UTC

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVE-2003-1024 sun vulnerability CVSS: 7.2 20 Jan 2004, 05:00 UTC

Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.

CVE-2003-0999 sun vulnerability CVSS: 7.2 05 Jan 2004, 05:00 UTC

Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.

CVE-2003-1123 sun vulnerability CVSS: 7.5 31 Dec 2003, 05:00 UTC

Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.

CVE-2003-1229 sun vulnerability CVSS: 7.5 31 Dec 2003, 05:00 UTC

X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.

CVE-2003-1076 sun vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.

CVE-2003-1082 sun vulnerability CVSS: 7.2 31 Dec 2003, 05:00 UTC

Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.

CVE-2003-1516 sun vulnerability CVSS: 6.8 31 Dec 2003, 05:00 UTC

The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.

CVE-2003-1521 sun vulnerability CVSS: 6.4 31 Dec 2003, 05:00 UTC

Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

CVE-2003-1066 sun vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.

CVE-2003-1125 sun vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).

CVE-2003-1126 sun vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.

CVE-2003-1301 sun vulnerability CVSS: 5.0 31 Dec 2003, 05:00 UTC

Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.

CVE-2003-1124 sun vulnerability CVSS: 4.6 31 Dec 2003, 05:00 UTC

Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.

CVE-2003-1156 sun vulnerability CVSS: 4.6 31 Dec 2003, 05:00 UTC

Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

CVE-2003-1563 sun vulnerability CVSS: 4.0 31 Dec 2003, 05:00 UTC

Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.

CVE-2003-1134 sun vulnerability CVSS: 2.1 31 Dec 2003, 05:00 UTC

Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

CVE-2003-1073 sun vulnerability CVSS: 1.2 31 Dec 2003, 05:00 UTC

A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.

CVE-2003-0970 sun vulnerability CVSS: 5.0 15 Dec 2003, 05:00 UTC

The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.

CVE-2003-0914 sun vulnerability CVSS: 4.3 15 Dec 2003, 05:00 UTC

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

CVE-2003-1056 sun vulnerability CVSS: 7.2 11 Dec 2003, 05:00 UTC

The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

CVE-2003-1057 sun vulnerability CVSS: 7.2 08 Dec 2003, 05:00 UTC

Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.

CVE-2003-1058 sun vulnerability CVSS: 3.7 03 Dec 2003, 05:00 UTC

The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.

CVE-2003-1059 sun vulnerability CVSS: 7.2 20 Nov 2003, 05:00 UTC

Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.

CVE-2003-0896 sun vulnerability CVSS: 7.5 17 Nov 2003, 05:00 UTC

The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.

CVE-2003-1060 sun vulnerability CVSS: 5.0 27 Oct 2003, 05:00 UTC

The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.

CVE-2003-1061 sun vulnerability CVSS: 1.2 14 Oct 2003, 04:00 UTC

Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.

CVE-2003-0694 sun vulnerability CVSS: 10.0 06 Oct 2003, 04:00 UTC

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVE-2003-0722 sun vulnerability CVSS: 10.0 22 Sep 2003, 04:00 UTC

The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.

CVE-2003-1081 sun vulnerability CVSS: 10.0 09 Sep 2003, 04:00 UTC

Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.

CVE-2003-0466 sun vulnerability CVSS: 10.0 27 Aug 2003, 04:00 UTC

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

CVE-2003-0609 sun vulnerability CVSS: 7.2 27 Aug 2003, 04:00 UTC

Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.

CVE-2003-0676 sun vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.

CVE-2003-0669 sun vulnerability CVSS: 1.2 27 Aug 2003, 04:00 UTC

Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.

CVE-2003-1063 sun vulnerability CVSS: 7.5 20 Aug 2003, 04:00 UTC

The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.

CVE-2003-1065 sun vulnerability CVSS: 2.1 23 Jul 2003, 04:00 UTC

Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow local users to cause a denial of service (automountd crash).

CVE-2003-1055 sun vulnerability CVSS: 7.2 03 Jul 2003, 04:00 UTC

Buffer overflow in the nss_ldap.so.1 library for Sun Solaris 8 and 9 may allow local users to gain root access via a long hostname in an LDAP lookup.

CVE-2003-0414 sun vulnerability CVSS: 7.2 30 Jun 2003, 04:00 UTC

The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.

CVE-2003-0413 sun vulnerability CVSS: 6.8 30 Jun 2003, 04:00 UTC

Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.

CVE-2003-0412 sun vulnerability CVSS: 5.0 30 Jun 2003, 04:00 UTC

Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.

CVE-2003-1067 sun vulnerability CVSS: 7.2 19 Jun 2003, 04:00 UTC

Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.

CVE-2003-1068 sun vulnerability CVSS: 7.2 06 Jun 2003, 04:00 UTC

Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.

CVE-2003-1069 sun vulnerability CVSS: 5.0 03 Jun 2003, 04:00 UTC

The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).

CVE-2003-0196 sun vulnerability CVSS: 10.0 05 May 2003, 04:00 UTC

Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.

CVE-2003-0201 sun vulnerability CVSS: 10.0 05 May 2003, 04:00 UTC

Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.

CVE-2003-1070 sun vulnerability CVSS: 5.0 28 Apr 2003, 04:00 UTC

Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).

CVE-2003-1072 sun vulnerability CVSS: 2.1 28 Apr 2003, 04:00 UTC

Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).

CVE-2003-0161 sun vulnerability CVSS: 10.0 02 Apr 2003, 05:00 UTC

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

CVE-2003-0091 sun vulnerability CVSS: 7.2 02 Apr 2003, 05:00 UTC

Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.

CVE-2003-0092 sun vulnerability CVSS: 7.2 02 Apr 2003, 05:00 UTC

Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.

CVE-2002-1525 sun vulnerability CVSS: 5.0 02 Apr 2003, 05:00 UTC

Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.

CVE-2003-1074 sun vulnerability CVSS: 7.2 28 Mar 2003, 05:00 UTC

Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.

CVE-2003-0028 sun vulnerability CVSS: 7.5 25 Mar 2003, 05:00 UTC

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

CVE-2002-0387 sun vulnerability CVSS: 7.5 18 Mar 2003, 05:00 UTC

Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.

CVE-2002-1337 sun vulnerability CVSS: 10.0 07 Mar 2003, 05:00 UTC

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

CVE-2003-1077 sun vulnerability CVSS: 2.1 05 Mar 2003, 05:00 UTC

Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).

CVE-2003-0064 sun vulnerability CVSS: 7.5 03 Mar 2003, 05:00 UTC

The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

CVE-2003-1078 sun vulnerability CVSS: 7.5 28 Feb 2003, 05:00 UTC

The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.

CVE-2003-0058 sun vulnerability CVSS: 5.0 19 Feb 2003, 05:00 UTC

MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.

CVE-2003-1079 sun vulnerability CVSS: 5.0 18 Feb 2003, 05:00 UTC

Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.

CVE-2003-0027 sun vulnerability CVSS: 5.0 07 Feb 2003, 05:00 UTC

Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.

CVE-2003-1075 sun vulnerability CVSS: 5.0 27 Jan 2003, 05:00 UTC

Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.

CVE-2003-1071 sun vulnerability CVSS: 2.1 03 Jan 2003, 05:00 UTC

rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.

CVE-2002-2374 sun vulnerability CVSS: 10.0 31 Dec 2002, 05:00 UTC

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

CVE-2002-2425 sun vulnerability CVSS: 10.0 31 Dec 2002, 05:00 UTC

Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

CVE-2002-2005 sun vulnerability CVSS: 7.5 31 Dec 2002, 05:00 UTC

Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.

CVE-2002-2036 sun vulnerability CVSS: 7.5 31 Dec 2002, 05:00 UTC

Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.

CVE-2002-1871 sun vulnerability CVSS: 7.2 31 Dec 2002, 05:00 UTC

pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.

CVE-2002-1980 sun vulnerability CVSS: 7.2 31 Dec 2002, 05:00 UTC

Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.

CVE-2002-2197 sun vulnerability CVSS: 7.2 31 Dec 2002, 05:00 UTC

Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference.

CVE-2002-2072 sun vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.

CVE-2002-2323 sun vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.

CVE-2002-2203 sun vulnerability CVSS: 4.9 31 Dec 2002, 05:00 UTC

Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.

CVE-2002-2327 sun vulnerability CVSS: 4.9 31 Dec 2002, 05:00 UTC

Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties.

CVE-2002-1763 sun vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.

CVE-2002-2089 sun vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.

CVE-2002-1584 sun vulnerability CVSS: 10.0 27 Dec 2002, 05:00 UTC

Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.

CVE-2002-1361 sun vulnerability CVSS: 10.0 23 Dec 2002, 05:00 UTC

overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.

CVE-2002-1296 sun vulnerability CVSS: 7.2 23 Dec 2002, 05:00 UTC

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

CVE-2002-1345 sun vulnerability CVSS: 5.0 23 Dec 2002, 05:00 UTC

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

CVE-2002-1344 sun vulnerability CVSS: 5.0 18 Dec 2002, 05:00 UTC

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

CVE-2002-1317 sun vulnerability CVSS: 7.5 11 Dec 2002, 05:00 UTC

Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.

CVE-2002-1323 sun vulnerability CVSS: 4.6 11 Dec 2002, 05:00 UTC

Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.

CVE-2002-1587 sun vulnerability CVSS: 2.1 04 Dec 2002, 05:00 UTC

The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.

CVE-2002-1586 sun vulnerability CVSS: 2.1 03 Dec 2002, 05:00 UTC

Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.

CVE-2002-1588 sun vulnerability CVSS: 5.0 29 Nov 2002, 05:00 UTC

Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.

CVE-2002-1585 sun vulnerability CVSS: 5.0 08 Nov 2002, 05:00 UTC

Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfaces to stop responding to TCP traffic.

CVE-2002-1590 sun vulnerability CVSS: 7.2 29 Oct 2002, 05:00 UTC

The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.

CVE-2002-1199 sun vulnerability CVSS: 5.0 28 Oct 2002, 05:00 UTC

The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.

CVE-2002-1228 sun vulnerability CVSS: 5.0 28 Oct 2002, 05:00 UTC

Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.

CVE-2002-1589 sun vulnerability CVSS: 2.1 24 Oct 2002, 04:00 UTC

Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).

CVE-2002-1034 sun vulnerability CVSS: 10.0 04 Oct 2002, 04:00 UTC

none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.

CVE-2002-0884 sun vulnerability CVSS: 7.5 04 Oct 2002, 04:00 UTC

Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execute arbitrary code via format strings that are not properly handled in the functions (1) syserr and (2) error.

CVE-2002-0885 sun vulnerability CVSS: 7.5 04 Oct 2002, 04:00 UTC

Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.

CVE-2002-0994 sun vulnerability CVSS: 7.5 04 Oct 2002, 04:00 UTC

SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.

CVE-2002-1033 sun vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument.

CVE-2002-1042 sun vulnerability CVSS: 5.0 04 Oct 2002, 04:00 UTC

Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

CVE-2002-0679 sun vulnerability CVSS: 10.0 05 Sep 2002, 04:00 UTC

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

CVE-2002-0391 sun vulnerability CVSS: 10.0 12 Aug 2002, 04:00 UTC

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.

CVE-2002-0796 sun vulnerability CVSS: 10.0 12 Aug 2002, 04:00 UTC

Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.

CVE-2002-0797 sun vulnerability CVSS: 10.0 12 Aug 2002, 04:00 UTC

Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.

CVE-2002-0430 sun vulnerability CVSS: 3.7 12 Aug 2002, 04:00 UTC

MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.

CVE-2002-0436 sun vulnerability CVSS: 10.0 26 Jul 2002, 04:00 UTC

sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.

CVE-2002-0677 sun vulnerability CVSS: 7.5 23 Jul 2002, 04:00 UTC

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

CVE-2002-0678 sun vulnerability CVSS: 7.2 23 Jul 2002, 04:00 UTC

CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

CVE-2002-0573 sun vulnerability CVSS: 7.5 03 Jul 2002, 04:00 UTC

Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.

CVE-2002-0572 sun vulnerability CVSS: 7.2 03 Jul 2002, 04:00 UTC

FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.

CVE-2002-0346 sun vulnerability CVSS: 7.5 25 Jun 2002, 04:00 UTC

Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.

CVE-2002-0348 sun vulnerability CVSS: 7.5 25 Jun 2002, 04:00 UTC

service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.

CVE-2002-0360 sun vulnerability CVSS: 7.5 25 Jun 2002, 04:00 UTC

Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program.

CVE-2002-0347 sun vulnerability CVSS: 5.0 25 Jun 2002, 04:00 UTC

Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.

CVE-2002-0033 sun vulnerability CVSS: 10.0 29 May 2002, 04:00 UTC

Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.

CVE-2002-0158 sun vulnerability CVSS: 7.2 02 Apr 2002, 05:00 UTC

Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.

CVE-2002-0076 sun vulnerability CVSS: 7.5 19 Mar 2002, 05:00 UTC

Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other implementations that use vulnerable versions of SDK or JDK, aka a variant of the "Virtual Machine Verifier" vulnerability.

CVE-2002-0084 sun vulnerability CVSS: 7.2 15 Mar 2002, 05:00 UTC

Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.

CVE-2002-0088 sun vulnerability CVSS: 7.2 15 Mar 2002, 05:00 UTC

Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.

CVE-2002-0089 sun vulnerability CVSS: 7.2 15 Mar 2002, 05:00 UTC

Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.

CVE-2002-0090 sun vulnerability CVSS: 7.2 15 Mar 2002, 05:00 UTC

Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.

CVE-2002-0058 sun vulnerability CVSS: 5.0 15 Mar 2002, 05:00 UTC

Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK.

CVE-2002-0085 sun vulnerability CVSS: 5.0 15 Mar 2002, 05:00 UTC

cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.

CVE-2001-1583 sun vulnerability CVSS: 10.0 31 Dec 2001, 05:00 UTC

lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.

CVE-2001-1480 sun vulnerability CVSS: 7.5 31 Dec 2001, 05:00 UTC

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

CVE-2001-1582 sun vulnerability CVSS: 7.2 31 Dec 2001, 05:00 UTC

Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.

CVE-2001-1555 sun vulnerability CVSS: 4.6 31 Dec 2001, 05:00 UTC

pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.

CVE-2001-1479 sun vulnerability CVSS: 2.1 31 Dec 2001, 05:00 UTC

smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.

CVE-2001-1503 sun vulnerability CVSS: 2.1 31 Dec 2001, 05:00 UTC

The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.

CVE-2001-0797 sun vulnerability CVSS: 10.0 12 Dec 2001, 05:00 UTC

Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.

CVE-2001-0922 sun vulnerability CVSS: 7.5 26 Nov 2001, 05:00 UTC

ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in.

CVE-2001-0652 sun vulnerability CVSS: 7.2 30 Oct 2001, 05:00 UTC

Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.

CVE-2001-0779 sun vulnerability CVSS: 10.0 18 Oct 2001, 04:00 UTC

Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.

CVE-2001-1414 sun vulnerability CVSS: 7.5 09 Oct 2001, 04:00 UTC

The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.

CVE-2001-0699 sun vulnerability CVSS: 7.2 20 Sep 2001, 04:00 UTC

Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.

CVE-2001-0701 sun vulnerability CVSS: 7.2 20 Sep 2001, 04:00 UTC

Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.

CVE-2001-0686 sun vulnerability CVSS: 4.6 20 Sep 2001, 04:00 UTC

Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.

CVE-2001-1008 sun vulnerability CVSS: 7.5 31 Aug 2001, 04:00 UTC

Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.

CVE-2001-1066 sun vulnerability CVSS: 2.1 31 Aug 2001, 04:00 UTC

ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.

CVE-2001-0632 sun vulnerability CVSS: 7.5 22 Aug 2001, 04:00 UTC

Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.

CVE-2001-0634 sun vulnerability CVSS: 7.2 22 Aug 2001, 04:00 UTC

Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service.

CVE-2001-0606 sun vulnerability CVSS: 5.0 22 Aug 2001, 04:00 UTC

Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.

CVE-2001-0633 sun vulnerability CVSS: 5.0 22 Aug 2001, 04:00 UTC

Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.

CVE-2001-0554 sun vulnerability CVSS: 10.0 14 Aug 2001, 04:00 UTC

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVE-2001-0526 sun vulnerability CVSS: 4.6 14 Aug 2001, 04:00 UTC

Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.

CVE-2001-0548 sun vulnerability CVSS: 4.6 14 Aug 2001, 04:00 UTC

Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.

CVE-2001-0565 sun vulnerability CVSS: 4.6 14 Aug 2001, 04:00 UTC

Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.

CVE-2001-0594 sun vulnerability CVSS: 4.6 02 Aug 2001, 04:00 UTC

kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.

CVE-2001-0595 sun vulnerability CVSS: 4.6 02 Aug 2001, 04:00 UTC

Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.

CVE-2001-0353 sun vulnerability CVSS: 10.0 21 Jul 2001, 04:00 UTC

Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.

CVE-2001-1306 sun vulnerability CVSS: 7.5 16 Jul 2001, 04:00 UTC

iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.

CVE-2001-1307 sun vulnerability CVSS: 7.5 16 Jul 2001, 04:00 UTC

Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

CVE-2001-1308 sun vulnerability CVSS: 7.5 16 Jul 2001, 04:00 UTC

Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

CVE-2001-1244 sun vulnerability CVSS: 5.0 07 Jul 2001, 04:00 UTC

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

CVE-2001-1076 sun vulnerability CVSS: 7.2 05 Jul 2001, 04:00 UTC

Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.

CVE-2001-1075 sun vulnerability CVSS: 5.0 04 Jul 2001, 04:00 UTC

poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file.

CVE-2001-0422 sun vulnerability CVSS: 7.2 02 Jul 2001, 04:00 UTC

Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

CVE-2001-0423 sun vulnerability CVSS: 7.2 02 Jul 2001, 04:00 UTC

Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.

CVE-2001-0426 sun vulnerability CVSS: 7.2 02 Jul 2001, 04:00 UTC

Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.

CVE-2001-0421 sun vulnerability CVSS: 6.4 02 Jul 2001, 04:00 UTC

FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.

CVE-2001-0470 sun vulnerability CVSS: 7.2 27 Jun 2001, 04:00 UTC

Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.

CVE-2001-1328 sun vulnerability CVSS: 7.5 22 Jun 2001, 04:00 UTC

Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.

CVE-2001-0401 sun vulnerability CVSS: 7.2 18 Jun 2001, 04:00 UTC

Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

CVE-2001-0403 sun vulnerability CVSS: 7.2 18 Jun 2001, 04:00 UTC

/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.

CVE-2001-0404 sun vulnerability CVSS: 5.0 18 Jun 2001, 04:00 UTC

Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.

CVE-2001-0236 sun vulnerability CVSS: 10.0 03 May 2001, 04:00 UTC

Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.

CVE-2001-0269 sun vulnerability CVSS: 10.0 03 May 2001, 04:00 UTC

pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.

CVE-2001-0165 sun vulnerability CVSS: 7.2 03 May 2001, 04:00 UTC

Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.

CVE-2001-0229 sun vulnerability CVSS: 7.2 03 May 2001, 04:00 UTC

Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.

CVE-2001-0283 sun vulnerability CVSS: 6.4 03 May 2001, 04:00 UTC

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

CVE-2001-0190 sun vulnerability CVSS: 7.2 26 Mar 2001, 05:00 UTC

Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).

CVE-2001-0115 sun vulnerability CVSS: 7.2 12 Mar 2001, 05:00 UTC

Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.

CVE-2001-0124 sun vulnerability CVSS: 7.2 12 Mar 2001, 05:00 UTC

Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.

CVE-2001-0059 sun vulnerability CVSS: 6.2 12 Feb 2001, 05:00 UTC

patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.

CVE-2001-0077 sun vulnerability CVSS: 5.0 12 Feb 2001, 05:00 UTC

The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.

CVE-2001-0078 sun vulnerability CVSS: 2.1 12 Feb 2001, 05:00 UTC

in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.

CVE-2001-0095 sun vulnerability CVSS: 1.2 12 Feb 2001, 05:00 UTC

catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.

CVE-2000-1099 sun vulnerability CVSS: 5.1 09 Jan 2001, 05:00 UTC

Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.

CVE-2000-1156 sun vulnerability CVSS: 3.6 09 Jan 2001, 05:00 UTC

StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.

CVE-2000-0949 sun vulnerability CVSS: 7.2 19 Dec 2000, 05:00 UTC

Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.

CVE-2000-0958 sun vulnerability CVSS: 5.0 19 Dec 2000, 05:00 UTC

HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.

CVE-2000-1076 sun vulnerability CVSS: 10.0 11 Dec 2000, 05:00 UTC

Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.

CVE-2000-1075 sun vulnerability CVSS: 5.0 11 Dec 2000, 05:00 UTC

Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.

CVE-2000-0812 sun vulnerability CVSS: 10.0 14 Nov 2000, 05:00 UTC

The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

CVE-2000-0844 sun vulnerability CVSS: 10.0 14 Nov 2000, 05:00 UTC

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

CVE-2000-0697 sun vulnerability CVSS: 10.0 20 Oct 2000, 04:00 UTC

The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.

CVE-2000-0696 sun vulnerability CVSS: 7.5 20 Oct 2000, 04:00 UTC

The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

CVE-2000-0629 sun vulnerability CVSS: 7.5 12 Jul 2000, 04:00 UTC

The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

CVE-2000-0471 sun vulnerability CVSS: 7.2 14 Jun 2000, 04:00 UTC

Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.

CVE-2000-0442 sun vulnerability CVSS: 7.5 24 May 2000, 04:00 UTC

Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.

CVE-2000-0431 sun vulnerability CVSS: 7.5 22 May 2000, 04:00 UTC

Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.

CVE-2000-0407 sun vulnerability CVSS: 7.2 12 May 2000, 04:00 UTC

Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.

CVE-2000-0316 sun vulnerability CVSS: 7.2 24 Apr 2000, 04:00 UTC

Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.

CVE-2000-0317 sun vulnerability CVSS: 7.2 24 Apr 2000, 04:00 UTC

Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.

CVE-2000-0337 sun vulnerability CVSS: 7.2 24 Apr 2000, 04:00 UTC

Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.

CVE-2000-0320 sun vulnerability CVSS: 5.0 21 Apr 2000, 04:00 UTC

Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.

CVE-2000-0291 sun vulnerability CVSS: 4.6 16 Apr 2000, 04:00 UTC

Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.

CVE-2000-0234 sun vulnerability CVSS: 5.0 31 Mar 2000, 05:00 UTC

The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.

CVE-2000-0175 sun vulnerability CVSS: 10.0 09 Mar 2000, 05:00 UTC

Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.

CVE-2000-0174 sun vulnerability CVSS: 5.0 09 Mar 2000, 05:00 UTC

StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVE-2000-0210 sun vulnerability CVSS: 1.2 21 Feb 2000, 05:00 UTC

The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.

CVE-2000-0164 sun vulnerability CVSS: 7.2 20 Feb 2000, 05:00 UTC

The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.

CVE-2000-0117 sun vulnerability CVSS: 7.2 30 Jan 2000, 05:00 UTC

The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).

CVE-2000-0055 sun vulnerability CVSS: 7.2 06 Jan 2000, 05:00 UTC

Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.

CVE-2000-0069 sun vulnerability CVSS: 2.1 01 Jan 2000, 05:00 UTC

The recover program in Solstice Backup allows local users to restore sensitive files.

CVE-1999-1584 sun vulnerability CVSS: 10.0 31 Dec 1999, 05:00 UTC

Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.

CVE-1999-1588 sun vulnerability CVSS: 10.0 31 Dec 1999, 05:00 UTC

Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.

CVE-1999-1585 sun vulnerability CVSS: 7.2 31 Dec 1999, 05:00 UTC

The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.

CVE-1999-1586 sun vulnerability CVSS: 7.2 31 Dec 1999, 05:00 UTC

loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.

CVE-1999-1102 sun vulnerability CVSS: 2.1 31 Dec 1999, 05:00 UTC

lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.

CVE-1999-1587 sun vulnerability CVSS: 2.1 31 Dec 1999, 05:00 UTC

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

CVE-2000-0032 sun vulnerability CVSS: 10.0 22 Dec 1999, 05:00 UTC

Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.

CVE-2000-0030 sun vulnerability CVSS: 5.0 22 Dec 1999, 05:00 UTC

Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.

CVE-1999-0977 sun vulnerability CVSS: 10.0 10 Dec 1999, 05:00 UTC

Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.

CVE-1999-0974 sun vulnerability CVSS: 10.0 09 Dec 1999, 05:00 UTC

Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.

CVE-1999-0973 sun vulnerability CVSS: 10.0 07 Dec 1999, 05:00 UTC

Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.

CVE-1999-0982 sun vulnerability CVSS: 7.2 05 Dec 1999, 05:00 UTC

The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.

CVE-1999-0859 sun vulnerability CVSS: 2.1 01 Dec 1999, 05:00 UTC

Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.

CVE-1999-0860 sun vulnerability CVSS: 2.1 01 Dec 1999, 05:00 UTC

Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.

CVE-1999-0840 sun vulnerability CVSS: 7.2 30 Nov 1999, 05:00 UTC

Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.

CVE-1999-0841 sun vulnerability CVSS: 7.2 30 Nov 1999, 05:00 UTC

Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.

CVE-1999-1527 sun vulnerability CVSS: 7.5 23 Nov 1999, 05:00 UTC

Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.

CVE-1999-0818 sun vulnerability CVSS: 7.2 20 Nov 1999, 05:00 UTC

Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.

CVE-1999-0831 sun vulnerability CVSS: 5.0 19 Nov 1999, 05:00 UTC

Denial of service in Linux syslogd via a large number of connections.

CVE-1999-0835 sun vulnerability CVSS: 10.0 10 Nov 1999, 05:00 UTC

Denial of service in BIND named via malformed SIG records.

CVE-1999-0837 sun vulnerability CVSS: 10.0 10 Nov 1999, 05:00 UTC

Denial of service in BIND by improperly closing TCP sessions via so_linger.

CVE-1999-0833 sun vulnerability CVSS: 7.5 10 Nov 1999, 05:00 UTC

Buffer overflow in BIND 8.2 via NXT records.

CVE-1999-0848 sun vulnerability CVSS: 5.0 10 Nov 1999, 05:00 UTC

Denial of service in BIND named via consuming more than "fdmax" file descriptors.

CVE-1999-0851 sun vulnerability CVSS: 2.1 10 Nov 1999, 05:00 UTC

Denial of service in BIND named via naptr.

CVE-1999-1530 sun vulnerability CVSS: 3.6 08 Nov 1999, 05:00 UTC

cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.

CVE-1999-0948 sun vulnerability CVSS: 7.2 02 Nov 1999, 05:00 UTC

Buffer overflow in uum program for Canna input system allows local users to gain root privileges.

CVE-1999-0949 sun vulnerability CVSS: 7.2 02 Nov 1999, 05:00 UTC

Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.

CVE-1999-0908 sun vulnerability CVSS: 5.0 23 Sep 1999, 04:00 UTC

Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.

CVE-1999-0786 sun vulnerability CVSS: 4.6 22 Sep 1999, 04:00 UTC

The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.

CVE-1999-0687 sun vulnerability CVSS: 7.5 13 Sep 1999, 04:00 UTC

The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

CVE-1999-0689 sun vulnerability CVSS: 7.2 13 Sep 1999, 04:00 UTC

The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.

CVE-1999-0691 sun vulnerability CVSS: 7.2 13 Sep 1999, 04:00 UTC

Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

CVE-1999-1014 sun vulnerability CVSS: 4.6 13 Sep 1999, 04:00 UTC

Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.

CVE-1999-0767 sun vulnerability CVSS: 7.2 08 Sep 1999, 04:00 UTC

Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.

CVE-1999-0875 sun vulnerability CVSS: 7.5 11 Aug 1999, 04:00 UTC

DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.

CVE-1999-0674 sun vulnerability CVSS: 7.2 09 Aug 1999, 04:00 UTC

The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

CVE-1999-0676 sun vulnerability CVSS: 4.6 09 Aug 1999, 04:00 UTC

sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.

CVE-1999-0722 sun vulnerability CVSS: 10.0 08 Aug 1999, 04:00 UTC

The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.

CVE-1999-0696 sun vulnerability CVSS: 10.0 01 Jul 1999, 04:00 UTC

Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).

CVE-1999-1023 sun vulnerability CVSS: 4.6 10 Jun 1999, 04:00 UTC

useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.

CVE-2000-0118 sun vulnerability CVSS: 7.2 09 Jun 1999, 04:00 UTC

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

CVE-1999-0493 sun vulnerability CVSS: 7.5 07 Jun 1999, 04:00 UTC

rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.

CVE-1999-0773 sun vulnerability CVSS: 7.2 11 May 1999, 04:00 UTC

Buffer overflow in Solaris lpset program allows local users to gain root access.

CVE-1999-0806 sun vulnerability CVSS: 7.2 10 May 1999, 04:00 UTC

Buffer overflow in Solaris dtprintinfo program.

CVE-1999-0417 sun vulnerability CVSS: 2.1 09 Mar 1999, 05:00 UTC

64 bit Solaris 7 procfs allows local users to perform a denial of service.

CVE-1999-1371 sun vulnerability CVSS: 7.2 08 Mar 1999, 05:00 UTC

Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.

CVE-1999-0410 sun vulnerability CVSS: 7.2 05 Mar 1999, 05:00 UTC

The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.

CVE-1999-0440 sun vulnerability CVSS: 7.5 01 Mar 1999, 05:00 UTC

The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.

CVE-1999-0223 sun vulnerability CVSS: 2.1 01 Mar 1999, 05:00 UTC

Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.

CVE-1999-0408 sun vulnerability CVSS: 10.0 25 Feb 1999, 05:00 UTC

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

CVE-1999-0370 sun vulnerability CVSS: 4.6 10 Feb 1999, 05:00 UTC

In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.

CVE-1999-0952 sun vulnerability CVSS: 7.2 28 Jan 1999, 05:00 UTC

Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

CVE-1999-0442 sun vulnerability CVSS: 2.1 07 Jan 1999, 05:00 UTC

Solaris ff.core allows local users to modify files.

CVE-1999-0568 sun vulnerability CVSS: 10.0 01 Jan 1999, 05:00 UTC

rpc.admind in Solaris is not running in a secure mode.

CVE-1999-0188 sun vulnerability CVSS: 7.2 17 Dec 1998, 05:00 UTC

The passwd command in Solaris can be subjected to a denial of service.

CVE-1999-0139 sun vulnerability CVSS: 7.2 12 Dec 1998, 05:00 UTC

Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.

CVE-1999-0321 sun vulnerability CVSS: 7.2 01 Dec 1998, 05:00 UTC

Buffer overflow in Solaris kcms_configure command allows local users to gain root access.

CVE-1999-0057 sun vulnerability CVSS: 7.5 16 Nov 1998, 05:00 UTC

Vacation program allows command execution by remote users through a sendmail command.

CVE-1999-1025 sun vulnerability CVSS: 4.6 12 Nov 1998, 05:00 UTC

CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.

CVE-1999-0254 sun vulnerability CVSS: 10.0 02 Nov 1998, 05:00 UTC

A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.

CVE-1999-0186 sun vulnerability CVSS: 10.0 01 Oct 1998, 04:00 UTC

In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.

CVE-1999-0056 sun vulnerability CVSS: 7.2 09 Sep 1998, 04:00 UTC

Buffer overflow in Sun's ping program can give root access to local users.

CVE-1999-0302 sun vulnerability CVSS: 7.5 01 Sep 1998, 04:00 UTC

SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.

CVE-1999-0065 sun vulnerability CVSS: 7.5 31 Aug 1998, 04:00 UTC

Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.

CVE-1999-0339 sun vulnerability CVSS: 7.2 01 Aug 1998, 04:00 UTC

Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.

CVE-1999-1432 sun vulnerability CVSS: 7.5 16 Jul 1998, 04:00 UTC

Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.

CVE-1999-0263 sun vulnerability CVSS: 4.6 16 Jul 1998, 04:00 UTC

Solaris SUNWadmap can be exploited to obtain root access.

CVE-1999-0213 sun vulnerability CVSS: 10.0 15 Jul 1998, 04:00 UTC

libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.

CVE-1999-1297 sun vulnerability CVSS: 2.1 15 Jul 1998, 04:00 UTC

cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.

CVE-1999-0797 sun vulnerability CVSS: 2.6 29 Jun 1998, 04:00 UTC

NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.

CVE-1999-0054 sun vulnerability CVSS: 5.0 10 Jun 1998, 04:00 UTC

Sun's ftpd daemon can be subjected to a denial of service.

CVE-1999-0008 sun vulnerability CVSS: 10.0 08 Jun 1998, 04:00 UTC

Buffer overflow in NIS+, in Sun's rpc.nisd program.

CVE-1999-0303 sun vulnerability CVSS: 4.6 21 May 1998, 04:00 UTC

Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.

CVE-1999-0055 sun vulnerability CVSS: 7.2 14 May 1998, 04:00 UTC

Buffer overflows in Sun libnsl allow root access.

CVE-1999-1027 sun vulnerability CVSS: 7.2 07 May 1998, 04:00 UTC

Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.

CVE-1999-0212 sun vulnerability CVSS: 7.8 29 Apr 1998, 04:00 UTC

Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.

CVE-1999-0069 sun vulnerability CVSS: 7.2 29 Apr 1998, 04:00 UTC

Solaris ufsrestore buffer overflow.

CVE-1999-0009 sun vulnerability CVSS: 10.0 08 Apr 1998, 04:00 UTC

Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

CVE-1999-0011 sun vulnerability CVSS: 10.0 08 Apr 1998, 04:00 UTC

Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

CVE-1999-0190 sun vulnerability CVSS: 7.2 08 Apr 1998, 04:00 UTC

Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.

CVE-1999-0010 sun vulnerability CVSS: 5.0 08 Apr 1998, 04:00 UTC

Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

CVE-1999-0003 sun vulnerability CVSS: 10.0 01 Apr 1998, 05:00 UTC

Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).

CVE-1999-1118 sun vulnerability CVSS: 2.1 11 Mar 1998, 05:00 UTC

ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.

CVE-1999-0320 sun vulnerability CVSS: 9.3 01 Mar 1998, 05:00 UTC

SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.

CVE-1999-0502 sun vulnerability CVSS: 7.5 01 Mar 1998, 05:00 UTC

A Unix account has a default, null, blank, or missing password.

CVE-1999-0795 sun vulnerability CVSS: 7.5 01 Mar 1998, 05:00 UTC

The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.

CVE-1999-0296 sun vulnerability CVSS: 7.2 01 Feb 1998, 05:00 UTC

Solaris volrmmount program allows attackers to read any file.

CVE-1999-0125 sun vulnerability CVSS: 4.6 25 Jan 1998, 05:00 UTC

Buffer overflow in SGI IRIX mailx program.

CVE-1999-0513 sun vulnerability CVSS: 5.0 05 Jan 1998, 05:00 UTC

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

CVE-1999-0273 sun vulnerability CVSS: 5.0 01 Jan 1998, 05:00 UTC

Denial of service through Solaris 2.5.1 telnet by sending ^D characters.

CVE-1999-0015 sun vulnerability CVSS: 5.0 16 Dec 1997, 05:00 UTC

Teardrop IP denial of service.

CVE-1999-0104 sun vulnerability CVSS: 5.0 16 Dec 1997, 05:00 UTC

A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.

CVE-1999-0017 sun vulnerability CVSS: 7.5 10 Dec 1997, 05:00 UTC

FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

CVE-1999-0018 sun vulnerability CVSS: 10.0 05 Dec 1997, 05:00 UTC

Buffer overflow in statd allows root privileges.

CVE-1999-0016 sun vulnerability CVSS: 5.0 01 Dec 1997, 05:00 UTC

Land IP denial of service.

CVE-1999-0210 sun vulnerability CVSS: 10.0 26 Nov 1997, 05:00 UTC

Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.

CVE-1999-1424 sun vulnerability CVSS: 6.2 10 Nov 1997, 05:00 UTC

Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

CVE-1999-1425 sun vulnerability CVSS: 6.2 10 Nov 1997, 05:00 UTC

Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.

CVE-1999-1426 sun vulnerability CVSS: 6.2 10 Nov 1997, 05:00 UTC

Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.

CVE-1999-1427 sun vulnerability CVSS: 6.2 10 Nov 1997, 05:00 UTC

Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.

CVE-1999-1428 sun vulnerability CVSS: 6.2 10 Nov 1997, 05:00 UTC

Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.

CVE-1999-0097 sun vulnerability CVSS: 10.0 29 Oct 1997, 05:00 UTC

The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).

CVE-1999-0185 sun vulnerability CVSS: 7.5 01 Oct 1997, 04:00 UTC

In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.

CVE-1999-0300 sun vulnerability CVSS: 7.5 01 Oct 1997, 04:00 UTC

nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.

CVE-1999-0295 sun vulnerability CVSS: 7.2 01 Oct 1997, 04:00 UTC

Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.

CVE-1999-1225 sun vulnerability CVSS: 5.0 24 Aug 1997, 04:00 UTC

rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.

CVE-1999-0024 sun vulnerability CVSS: 5.0 13 Aug 1997, 04:00 UTC

DNS cache poisoning via BIND, by predictable query IDs.

CVE-1999-0301 sun vulnerability CVSS: 7.2 01 Aug 1997, 04:00 UTC

Buffer overflow in SunOS/Solaris ps command.

CVE-1999-1419 sun vulnerability CVSS: 7.2 30 Jul 1997, 04:00 UTC

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVE-1999-0169 sun vulnerability CVSS: 10.0 01 Jul 1997, 04:00 UTC

NFS allows attackers to read and write any file on the system by specifying a false UID.

CVE-1999-1423 sun vulnerability CVSS: 2.1 26 Jun 1997, 04:00 UTC

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

CVE-1999-1192 sun vulnerability CVSS: 7.2 24 Jun 1997, 04:00 UTC

Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

CVE-1999-0033 sun vulnerability CVSS: 7.2 12 Jun 1997, 04:00 UTC

Command execution in Sun systems via buffer overflow in the at program.

CVE-1999-0189 sun vulnerability CVSS: 7.5 04 Jun 1997, 04:00 UTC

Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.

CVE-1999-1191 sun vulnerability CVSS: 7.2 19 May 1997, 04:00 UTC

Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

CVE-1999-1449 sun vulnerability CVSS: 2.1 19 May 1997, 04:00 UTC

SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.

CVE-1999-1402 sun vulnerability CVSS: 2.1 17 May 1997, 04:00 UTC

The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

CVE-1999-1158 sun vulnerability CVSS: 7.2 13 May 1997, 04:00 UTC

Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.

CVE-1999-0040 sun vulnerability CVSS: 7.2 01 May 1997, 04:00 UTC

Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

CVE-1999-0038 sun vulnerability CVSS: 7.2 26 Apr 1997, 04:00 UTC

Buffer overflow in xlock program allows local users to execute commands as root.

CVE-1999-0315 sun vulnerability CVSS: 7.2 01 Apr 1997, 05:00 UTC

Buffer overflow in Solaris fdformat command gives root access to local users.

CVE-1999-0165 sun vulnerability CVSS: 10.0 01 Mar 1997, 05:00 UTC

NFS cache poisoning.

CVE-1999-0318 sun vulnerability CVSS: 7.2 01 Mar 1997, 05:00 UTC

Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.

CVE-1999-0868 sun vulnerability CVSS: 7.2 20 Feb 1997, 05:00 UTC

ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.

CVE-1999-0109 sun vulnerability CVSS: 7.2 10 Feb 1997, 05:00 UTC

Buffer overflow in ffbconfig in Solaris 2.5.1.

CVE-1999-0046 sun vulnerability CVSS: 10.0 06 Feb 1997, 05:00 UTC

Buffer overflow of rlogin program using TERM environmental variable.

CVE-1999-0298 sun vulnerability CVSS: 7.5 05 Feb 1997, 05:00 UTC

ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

CVE-1999-0369 sun vulnerability CVSS: 7.2 01 Feb 1997, 05:00 UTC

The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.

CVE-1999-0966 sun vulnerability CVSS: 7.2 27 Jan 1997, 05:00 UTC

Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].

CVE-1999-0051 sun vulnerability CVSS: 7.2 06 Jan 1997, 05:00 UTC

Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.

CVE-1999-0517 sun vulnerability CVSS: 7.5 01 Jan 1997, 05:00 UTC

An SNMP community name is the default (e.g. public), null, or missing.

CVE-1999-0166 sun vulnerability CVSS: 5.0 01 Jan 1997, 05:00 UTC

NFS allows users to use a "cd .." command to access other directories besides the exported file system.

CVE-1999-0217 sun vulnerability CVSS: 5.0 01 Jan 1997, 05:00 UTC

Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.

CVE-1999-0345 sun vulnerability CVSS: 5.0 01 Jan 1997, 05:00 UTC

Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

CVE-1999-0626 sun vulnerability CVSS: 0 01 Jan 1997, 05:00 UTC

A version of rusers is running that exposes valid user information to any entity on the network.

CVE-1999-1026 sun vulnerability CVSS: 7.2 20 Dec 1996, 05:00 UTC

aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.

CVE-1999-0128 sun vulnerability CVSS: 5.0 18 Dec 1996, 05:00 UTC

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

CVE-1999-0129 sun vulnerability CVSS: 4.6 03 Dec 1996, 05:00 UTC

Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

CVE-1999-0277 sun vulnerability CVSS: 7.2 28 Oct 1996, 05:00 UTC

The WorkMan program can be used to overwrite any file to get root access.

CVE-1999-0032 sun vulnerability CVSS: 7.2 25 Oct 1996, 04:00 UTC

Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.

CVE-1999-0132 sun vulnerability CVSS: 2.1 15 Aug 1996, 04:00 UTC

Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.

CVE-1999-0134 sun vulnerability CVSS: 7.2 06 Aug 1996, 04:00 UTC

vold in Solaris 2.x allows local users to gain root access.

CVE-1999-1413 sun vulnerability CVSS: 4.6 03 Aug 1996, 04:00 UTC

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVE-1999-0136 sun vulnerability CVSS: 7.2 31 Jul 1996, 04:00 UTC

Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.

CVE-1999-0135 sun vulnerability CVSS: 7.2 25 Jul 1996, 04:00 UTC

admintool in Solaris allows a local user to write to arbitrary files and gain root access.

CVE-1999-0023 sun vulnerability CVSS: 7.2 24 Jul 1996, 04:00 UTC

Local user gains root privileges via buffer overflow in rdist, via lookup() function.

CVE-1999-0022 sun vulnerability CVSS: 7.2 03 Jul 1996, 04:00 UTC

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

CVE-1999-0019 sun vulnerability CVSS: 5.0 24 Apr 1996, 04:00 UTC

Delete or create a file via rpc.statd, due to invalid information.

CVE-1999-0078 sun vulnerability CVSS: 1.9 18 Apr 1996, 04:00 UTC

pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

CVE-1999-0142 sun vulnerability CVSS: 7.5 01 Mar 1996, 05:00 UTC

The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.

CVE-1999-0143 sun vulnerability CVSS: 4.6 21 Feb 1996, 05:00 UTC

Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.

CVE-1999-0241 sun vulnerability CVSS: 10.0 01 Nov 1995, 05:00 UTC

Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.

CVE-1999-0099 sun vulnerability CVSS: 10.0 19 Oct 1995, 04:00 UTC

Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.

CVE-1999-0164 sun vulnerability CVSS: 6.2 29 Aug 1995, 04:00 UTC

A race condition in the Solaris ps command allows an attacker to overwrite critical files.

CVE-1999-1580 sun vulnerability CVSS: 7.2 23 Aug 1995, 04:00 UTC

SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.

CVE-1999-1080 sun vulnerability CVSS: 7.2 10 May 1995, 04:00 UTC

rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.

CVE-1999-1388 sun vulnerability CVSS: 6.2 13 May 1994, 04:00 UTC

passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.

CVE-1999-0120 sun vulnerability CVSS: 7.2 21 Mar 1994, 05:00 UTC

Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.

CVE-1999-0211 sun vulnerability CVSS: 5.0 14 Feb 1994, 05:00 UTC

Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.

CVE-1999-0334 sun vulnerability CVSS: 7.2 16 Dec 1993, 05:00 UTC

In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.

CVE-1999-1137 sun vulnerability CVSS: 2.1 01 Oct 1993, 04:00 UTC

The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.

CVE-1999-1318 sun vulnerability CVSS: 7.2 17 Sep 1993, 04:00 UTC

/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.

CVE-1999-1507 sun vulnerability CVSS: 7.2 03 Feb 1993, 05:00 UTC

Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.

CVE-1999-1021 sun vulnerability CVSS: 7.2 30 Dec 1992, 05:00 UTC

NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.

CVE-1999-0214 sun vulnerability CVSS: 10.0 21 Jul 1992, 04:00 UTC

Denial of service by sending forged ICMP unreachable packets.

CVE-1999-1396 sun vulnerability CVSS: 7.2 21 Jul 1992, 04:00 UTC

Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).

CVE-1999-0168 sun vulnerability CVSS: 7.5 04 Jun 1992, 04:00 UTC

The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.

CVE-1999-1142 sun vulnerability CVSS: 7.2 27 May 1992, 04:00 UTC

SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.

CVE-1999-0167 sun vulnerability CVSS: 4.6 06 Dec 1991, 05:00 UTC

In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.

CVE-1999-1468 sun vulnerability CVSS: 6.2 22 Oct 1991, 04:00 UTC

rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.

CVE-1999-1123 sun vulnerability CVSS: 7.2 20 May 1991, 04:00 UTC

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

CVE-1999-1211 sun vulnerability CVSS: 7.2 27 Mar 1991, 05:00 UTC

Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.

CVE-1999-1212 sun vulnerability CVSS: 7.2 27 Mar 1991, 05:00 UTC

Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.

CVE-1999-1438 sun vulnerability CVSS: 7.2 22 Feb 1991, 05:00 UTC

Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.

CVE-1999-1258 sun vulnerability CVSS: 5.0 15 Jan 1991, 05:00 UTC

rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.

CVE-1999-1197 sun vulnerability CVSS: 7.2 20 Dec 1990, 05:00 UTC

TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.

CVE-1999-0209 sun vulnerability CVSS: 5.0 14 Aug 1990, 04:00 UTC

The SunView (SunTools) selection_svc facility allows remote users to read files.

CVE-1999-0084 sun vulnerability CVSS: 7.2 01 May 1990, 04:00 UTC

Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.

CVE-1999-1506 sun vulnerability CVSS: 7.5 29 Jan 1990, 05:00 UTC

Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.

CVE-1999-1467 sun vulnerability CVSS: 10.0 26 Oct 1989, 04:00 UTC

Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.

CVE-1999-1122 sun vulnerability CVSS: 4.6 26 Jul 1989, 04:00 UTC

Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.