SunCVEs & Vulnerabilities

1,711 CVEs affecting Sun products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

1,711 CVEs→ All vendors

Most Affected Products

jre 6,495opensolaris 5,914sdk 4,078jdk 3,312sunos 1,461solaris 1,104java system identity manager 68j2se 55
CVE-2001-0401HIGHpoc

Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

18 Jun 2001
7.2
CVSS
CVE-2001-0229HIGH

Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.

3 May 2001
7.2
CVSS
CVE-2001-0269CRITICAL

pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.

3 May 2001
10.0
CVSS
CVE-2001-0283MEDIUMpoc

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

3 May 2001
6.4
CVSS
CVE-2001-0165HIGHpoc

Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.

3 May 2001
7.2
CVSS
CVE-2001-0236CRITICALpoc

Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.

3 May 2001
10.0
CVSS
CVE-2001-0190HIGH

Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).

26 Mar 2001
7.2
CVSS
CVE-2001-0124HIGH

Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.

12 Mar 2001
7.2
CVSS
CVE-2001-0115HIGHpoc

Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.

12 Mar 2001
7.2
CVSS
CVE-2001-0077MEDIUM

The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.

12 Feb 2001
5.0
CVSS
CVE-2001-0078LOW

in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.

12 Feb 2001
2.1
CVSS
CVE-2001-0059MEDIUMpoc

patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.

12 Feb 2001
6.2
CVSS
CVE-2001-0095LOWpoc

catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.

12 Feb 2001
1.2
CVSS
CVE-2000-1099MEDIUM

Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.

9 Jan 2001
5.1
CVSS
CVE-2000-1156LOW

StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.

9 Jan 2001
3.6
CVSS
CVE-2000-0949HIGHpoc

Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.

19 Dec 2000
7.2
CVSS
CVE-2000-0958MEDIUMpoc

HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.

19 Dec 2000
5.0
CVSS
CVE-2000-1076CRITICAL

Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.

11 Dec 2000
10.0
CVSS
CVE-2000-1075MEDIUMpoc

Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.

11 Dec 2000
5.0
CVSS
CVE-2000-0812CRITICAL

The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

14 Nov 2000
10.0
CVSS
CVE-2000-0844CRITICALpoc

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

14 Nov 2000
10.0
CVSS
CVE-2000-0696HIGHpoc

The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

20 Oct 2000
7.5
CVSS
CVE-2000-0697CRITICALpoc

The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.

20 Oct 2000
10.0
CVSS
CVE-2000-0629HIGH

The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

12 Jul 2000
7.5
CVSS
CVE-2000-0471HIGHpoc

Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.

14 Jun 2000
7.2
CVSS
CVE-2000-0442HIGHpoc

Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.

24 May 2000
7.5
CVSS
CVE-2000-0431HIGH

Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.

22 May 2000
7.5
CVSS
CVE-2000-0407HIGHpoc

Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.

12 May 2000
7.2
CVSS
CVE-2000-0316HIGHpoc

Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.

24 Apr 2000
7.2
CVSS
CVE-2000-0317HIGHpoc

Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.

24 Apr 2000
7.2
CVSS
CVE-2000-0337HIGHpoc

Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.

24 Apr 2000
7.2
CVSS
CVE-2000-0320MEDIUM

Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.

21 Apr 2000
5.0
CVSS
CVE-2000-0291MEDIUM

Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.

16 Apr 2000
4.6
CVSS
CVE-2000-0234MEDIUMpoc

The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.

31 Mar 2000
5.0
CVSS
CVE-2000-0175CRITICAL

Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.

9 Mar 2000
10.0
CVSS
CVE-2000-0174MEDIUMpoc

StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

9 Mar 2000
5.0
CVSS
CVE-2000-0210LOWpoc

The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.

21 Feb 2000
1.2
CVSS
CVE-2000-0164HIGH

The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.

20 Feb 2000
7.2
CVSS
CVE-2000-0117HIGH

The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).

30 Jan 2000
7.2
CVSS
CVE-2000-0055HIGH

Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.

6 Jan 2000
7.2
CVSS
CVE-2000-0069LOW

The recover program in Solstice Backup allows local users to restore sensitive files.

1 Jan 2000
2.1
CVSS
CVE-1999-1102LOW

lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.

31 Dec 1999
2.1
CVSS
CVE-1999-1584CRITICAL

Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.

31 Dec 1999
10.0
CVSS
CVE-1999-1585HIGH

The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.

31 Dec 1999
7.2
CVSS
CVE-1999-1586HIGH

loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.

31 Dec 1999
7.2
CVSS
CVE-1999-1592HIGH

Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact. NOTE: this might overlap CVE-1999-0129.

31 Dec 1999
7.5
CVSS
CVE-1999-1587LOWpoc

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

31 Dec 1999
2.1
CVSS
CVE-1999-1588CRITICALpoc

Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.

31 Dec 1999
9.8
CVSS
← PrevPage 32 / 36Next →