Skip to content
Noroxi

sun records

1,711 published records for vendor sun.

All records

1,711 records
  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    oracle · jreJun 18, 2013

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    oracle · jreJun 7, 2012

  • CVE-2007-0882
    69This week

    Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "

    CriticalCVSS 10.0WeaponizedEPSS 98%

    sun · sunosFeb 12, 2007

  • CVE-2001-0797
    68This week

    Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe

    CriticalCVSS 10.0WeaponizedEPSS 95%

    sgi · irixDec 12, 2001

  • CVE-2003-0722
    67This week

    The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstic

    CriticalCVSS 10.0WeaponizedEPSS 89%

    sun · solarisSep 22, 2003

  • CVE-2011-2110
    66This week

    Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attack

    CriticalCVSS 10.0WeaponizedEPSS 86%

    adobe · flash playerJun 16, 2011

  • CVE-2013-1493
    66This week

    The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Upd

    CriticalCVSS 10.0WeaponizedEPSS 86%

    oracle · jreMar 5, 2013

  • CVE-2008-5353
    66This week

    The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2

    CriticalCVSS 10.0WeaponizedEPSS 86%

    sun · jdkDec 5, 2008

  • CVE-2003-0201
    65This week

    Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG

    CriticalCVSS 10.0WeaponizedEPSS 85%

    samba · sambaMay 5, 2003

  • CVE-2010-3563
    65This week

    Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect

    CriticalCVSS 10.0WeaponizedEPSS 84%

    sun · jreOct 19, 2010

  • CVE-2001-1583
    65This week

    lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control

    CriticalCVSS 10.0WeaponizedEPSS 83%

    sun · sunosDec 31, 2001

  • CVE-2010-4452
    65This week

    Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23

    CriticalCVSS 10.0WeaponizedEPSS 83%

    sun · jreFeb 17, 2011

  • CVE-2011-2140
    65This week

    Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 o

    CriticalCVSS 10.0WeaponizedEPSS 82%

    adobe · flash playerAug 10, 2011

  • CVE-2010-3552
    64This week

    Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to a

    CriticalCVSS 10.0WeaponizedEPSS 81%

    sun · jreOct 19, 2010

  • CVE-2010-0361
    64This week

    Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote att

    CriticalCVSS 10.0WeaponizedEPSS 80%

    sun · java system web serverJan 20, 2010

  • CVE-2003-0466
    62This week

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    CriticalCVSS 9.8Proof of conceptEPSS 78%

    redhat · wu ftpdAug 27, 2003

  • CVE-2002-1337
    62This week

    Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t

    CriticalCVSS 10.0Proof of conceptEPSS 73%

    sendmail · sendmailMar 7, 2003

  • CVE-2001-0236
    62This week

    Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"

    CriticalCVSS 10.0Proof of conceptEPSS 72%

    sun · solarisMay 3, 2001

  • CVE-2010-0886
    61This week

    Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1

    CriticalCVSS 10.0WeaponizedEPSS 70%

    sun · jreApr 20, 2010

  • CVE-2008-4556
    61This week

    Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers

    CriticalCVSS 10.0WeaponizedEPSS 70%

    sun · solarisOct 14, 2008

  • CVE-2012-1533
    61This week

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earl

    CriticalCVSS 10.0WeaponizedEPSS 69%

    oracle · jdkOct 16, 2012

  • CVE-2008-0960
    61This week

    SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J

    CriticalCVSS 10.0Proof of conceptEPSS 69%

    net-snmp · net snmpJun 10, 2008

  • CVE-2003-0694
    60This week

    The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using

    CriticalCVSS 10.0WeaponizedEPSS 66%

    sendmail · advanced message serverOct 6, 2003

  • Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before

    CriticalCVSS 9.3WeaponizedEPSS 73%

    sun · jdkNov 5, 2009

  • Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.

    CriticalCVSS 10.0Proof of conceptEPSS 62%

    sun · solarisOct 18, 2001