Filtered by vendor Sun Subscriptions
Total 1712 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-1999-0689 2 Cde, Sun 3 Cde, Solaris, Sunos 2025-04-03 N/A
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
CVE-1999-0687 4 Cde, Digital, Ibm and 1 more 5 Cde, Unix, Aix and 2 more 2025-04-03 N/A
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVE-1999-0241 3 Sgi, Sun, Xfree86 Project 4 Irix, Solaris, Sunos and 1 more 2025-04-03 N/A
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
CVE-1999-0223 1 Sun 1 Sunos 2025-04-03 N/A
Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.
CVE-1999-0442 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Solaris ff.core allows local users to modify files.
CVE-1999-0213 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
CVE-2003-0722 1 Sun 1 Solaris 2025-04-03 N/A
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.
CVE-1999-0212 1 Sun 1 Sunos 2025-04-03 N/A
Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.
CVE-1999-0210 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
CVE-2006-3225 1 Sun 2 Java System Application Server, One Application Server 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors.
CVE-2003-0999 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.
CVE-2005-3071 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.
CVE-2005-3250 1 Sun 1 Solaris 2025-04-03 N/A
Unknown vulnerability in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors related to the "/proc" filesystem, which trigger a null dereference.
CVE-1999-0417 1 Sun 1 Sunos 2025-04-03 N/A
64 bit Solaris 7 procfs allows local users to perform a denial of service.
CVE-2005-3269 1 Sun 4 Java System Directory Proxy Server, Java System Directory Server, One Administration Server and 1 more 2025-04-03 N/A
Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges.
CVE-1999-0190 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
CVE-1999-0189 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
CVE-1999-0188 1 Sun 2 Solaris, Sunos 2025-04-03 N/A
The passwd command in Solaris can be subjected to a denial of service.
CVE-2001-0404 1 Sun 1 Javaserver Web Dev Kit 2025-04-03 N/A
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.
CVE-1999-0169 1 Sun 1 Nfs 2025-04-03 N/A
NFS allows attackers to read and write any file on the system by specifying a false UID.