Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Total 1711 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0211 1 Sun 1 Sunos 2025-04-03 5.0 MEDIUM N/A
Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.
CVE-2005-3472 1 Sun 1 Java System Communications Express 2025-04-03 5.0 MEDIUM N/A
Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.
CVE-1999-1258 1 Sun 1 Sunos 2025-04-03 5.0 MEDIUM N/A
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.
CVE-2001-1308 1 Sun 1 Iplanet Directory Server 2025-04-03 7.5 HIGH N/A
Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
CVE-2005-2094 1 Sun 1 One Web Server 2025-04-03 4.3 MEDIUM N/A
Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
CVE-2004-0802 9 Conectiva, Enlightenment, Imagemagick and 6 more 16 Linux, Imlib, Imlib2 and 13 more 2025-04-03 5.1 MEDIUM N/A
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
CVE-2005-0447 1 Sun 2 Solaris, Sunos 2025-04-03 5.0 MEDIUM N/A
Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.
CVE-1999-0833 2 Isc, Sun 3 Bind, Solaris, Sunos 2025-04-03 7.5 HIGH N/A
Buffer overflow in BIND 8.2 via NXT records.
CVE-1999-0626 1 Sun 1 Rpc.ruserd 2025-04-03 N/A N/A
A version of rusers is running that exposes valid user information to any entity on the network.
CVE-1999-0136 1 Sun 1 Sunos 2025-04-03 7.2 HIGH N/A
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
CVE-2001-0422 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
CVE-1999-0128 5 Digital, Ibm, Linux and 2 more 9 Osf 1, Aix, Sng and 6 more 2025-04-03 5.0 MEDIUM N/A
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
CVE-2001-0632 1 Sun 1 Chilisoft 2025-04-03 7.5 HIGH N/A
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
CVE-2005-0816 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
CVE-2004-0481 1 Sun 2 Solaris, Sunos 2025-04-03 2.1 LOW N/A
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
CVE-1999-0046 10 Bsdi, Debian, Digital and 7 more 10 Bsd Os, Debian Linux, Ultrix and 7 more 2025-04-03 10.0 HIGH N/A
Buffer overflow of rlogin program using TERM environmental variable.
CVE-2005-4133 1 Sun 1 Solaris 2025-04-03 2.1 LOW N/A
Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files.
CVE-2003-1061 1 Sun 2 Solaris, Sunos 2025-04-03 1.2 LOW N/A
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.
CVE-2002-1590 1 Sun 2 Solaris, Sunos 2025-04-03 7.2 HIGH N/A
The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
CVE-1999-0023 6 Bsdi, Freebsd, Ibm and 3 more 10 Bsd Os, Freebsd, Aix and 7 more 2025-04-03 7.2 HIGH N/A
Local user gains root privileges via buffer overflow in rdist, via lookup() function.