Vulnerabilities (CVE)

Filtered by vendor Sun Subscribe
Total 1700 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0128 5 Digital, Ibm, Linux and 2 more 9 Osf 1, Aix, Sng and 6 more 2023-12-10 5.0 MEDIUM N/A
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
CVE-2000-0175 1 Sun 1 Staroffice 2023-12-10 10.0 HIGH N/A
Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.
CVE-2004-1357 1 Sun 1 Solaris 2023-12-10 5.0 MEDIUM N/A
The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.
CVE-1999-0168 1 Sun 1 Sunos 2023-12-10 7.5 HIGH N/A
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.
CVE-2002-1228 1 Sun 2 Solaris, Sunos 2023-12-10 5.0 MEDIUM N/A
Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.
CVE-1999-0032 5 Bsdi, Freebsd, Next and 2 more 5 Bsd Os, Freebsd, Nextstep and 2 more 2023-12-10 7.2 HIGH N/A
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
CVE-2003-1076 1 Sun 2 Solaris, Sunos 2023-12-10 7.2 HIGH N/A
Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.
CVE-2002-2036 1 Sun 1 Ray Server Software 2023-12-10 7.5 HIGH N/A
Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.
CVE-2001-0922 1 Sun 1 Netdynamics 2023-12-10 7.5 HIGH N/A
ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in.
CVE-1999-0676 1 Sun 2 Solaris, Sunos 2023-12-10 4.6 MEDIUM N/A
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
CVE-1999-0502 3 Hp, Redhat, Sun 4 Hp-ux, Linux, Solaris and 1 more 2023-12-10 7.5 HIGH N/A
A Unix account has a default, null, blank, or missing password.
CVE-2001-0124 1 Sun 2 Solaris, Sunos 2023-12-10 7.2 HIGH N/A
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
CVE-1999-1021 1 Sun 1 Sunos 2023-12-10 7.2 HIGH N/A
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
CVE-2000-0844 13 Caldera, Conectiva, Debian and 10 more 16 Openlinux, Openlinux Ebuilder, Openlinux Eserver and 13 more 2023-12-10 10.0 HIGH N/A
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
CVE-1999-0568 1 Sun 1 Solaris 2023-12-10 10.0 HIGH N/A
rpc.admind in Solaris is not running in a secure mode.
CVE-1999-1192 1 Sun 1 Sunos 2023-12-10 7.2 HIGH N/A
Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
CVE-2001-0404 1 Sun 1 Javaserver Web Dev Kit 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.
CVE-1999-0303 4 Digital, Netbsd, Openbsd and 1 more 5 Osf 1, Netbsd, Openbsd and 2 more 2023-12-10 4.6 MEDIUM N/A
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
CVE-1999-1123 1 Sun 1 Sunos 2023-12-10 7.2 HIGH N/A
The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.
CVE-1999-0185 1 Sun 2 Solaris, Sunos 2023-12-10 7.5 HIGH N/A
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.