Filtered by vendor Sun
Subscriptions
Total
1712 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-1999-0689 | 2 Cde, Sun | 3 Cde, Solaris, Sunos | 2025-04-03 | N/A |
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack. | ||||
CVE-1999-0687 | 4 Cde, Digital, Ibm and 1 more | 5 Cde, Unix, Aix and 2 more | 2025-04-03 | N/A |
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. | ||||
CVE-1999-0241 | 3 Sgi, Sun, Xfree86 Project | 4 Irix, Solaris, Sunos and 1 more | 2025-04-03 | N/A |
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. | ||||
CVE-1999-0223 | 1 Sun | 1 Sunos | 2025-04-03 | N/A |
Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. | ||||
CVE-1999-0442 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Solaris ff.core allows local users to modify files. | ||||
CVE-1999-0213 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind. | ||||
CVE-2003-0722 | 1 Sun | 1 Solaris | 2025-04-03 | N/A |
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets. | ||||
CVE-1999-0212 | 1 Sun | 1 Sunos | 2025-04-03 | N/A |
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server. | ||||
CVE-1999-0210 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. | ||||
CVE-2006-3225 | 1 Sun | 2 Java System Application Server, One Application Server | 2025-04-03 | N/A |
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors. | ||||
CVE-2003-0999 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files. | ||||
CVE-2005-3071 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS. | ||||
CVE-2005-3250 | 1 Sun | 1 Solaris | 2025-04-03 | N/A |
Unknown vulnerability in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors related to the "/proc" filesystem, which trigger a null dereference. | ||||
CVE-1999-0417 | 1 Sun | 1 Sunos | 2025-04-03 | N/A |
64 bit Solaris 7 procfs allows local users to perform a denial of service. | ||||
CVE-2005-3269 | 1 Sun | 4 Java System Directory Proxy Server, Java System Directory Server, One Administration Server and 1 more | 2025-04-03 | N/A |
Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges. | ||||
CVE-1999-0190 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. | ||||
CVE-1999-0189 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. | ||||
CVE-1999-0188 | 1 Sun | 2 Solaris, Sunos | 2025-04-03 | N/A |
The passwd command in Solaris can be subjected to a denial of service. | ||||
CVE-2001-0404 | 1 Sun | 1 Javaserver Web Dev Kit | 2025-04-03 | N/A |
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory. | ||||
CVE-1999-0169 | 1 Sun | 1 Nfs | 2025-04-03 | N/A |
NFS allows attackers to read and write any file on the system by specifying a false UID. |