sun records
1,711 published records for vendor sun.
Researcher profile
- Entered KEV
- 2 · 0.1%
- Weaponized
- 37 · 2.2%
- Pre-auth RCE
- 202
- With a fix record
- 28.4%
- Median publish → KEV
- 3381 days
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls99
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer72
- CWE-399 Resource Management Errors47
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-20 Improper Input Validation33
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
The weakness classes this vendor ships most often: where to look.
CWEAll records
1,711 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2013-2465Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Critical9.8 | KEV | 98.8% | Jun 18, 2013 |
98Now | CVE-2012-0507Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Critical9.8 | KEV | 98.1% | Jun 7, 2012 |
69This week | CVE-2007-0882Weaponized | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "sun · sunos · CWE-88 | Critical10.0 | — | 98.0% | Feb 12, 2007 |
68This week | CVE-2001-0797Weaponized | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Critical10.0 | — | 94.7% | Dec 12, 2001 |
67This week | CVE-2003-0722Weaponized | The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solsticsun · solaris | Critical10.0 | — | 88.8% | Sep 22, 2003 |
66This week | CVE-2011-2110Weaponized | Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackadobe · flash player · CWE-119 | Critical10.0 | — | 86.4% | Jun 16, 2011 |
66This week | CVE-2013-1493Weaponized | The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Updoracle · jre · CWE-119 | Critical10.0 | — | 86.2% | Mar 5, 2013 |
66This week | CVE-2008-5353Weaponized | The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2sun · jdk | Critical10.0 | — | 85.8% | Dec 5, 2008 |
65This week | CVE-2003-0201Weaponized | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Critical10.0 | — | 84.5% | May 5, 2003 |
65This week | CVE-2010-3563Weaponized | Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect sun · jre | Critical10.0 | — | 84.3% | Oct 19, 2010 |
65This week | CVE-2001-1583Weaponized | lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control sun · sunos · CWE-78 | Critical10.0 | — | 83.4% | Dec 31, 2001 |
65This week | CVE-2010-4452Weaponized | Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 sun · jre | Critical10.0 | — | 82.8% | Feb 17, 2011 |
65This week | CVE-2011-2140Weaponized | Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 oadobe · flash player · CWE-119 | Critical10.0 | — | 82.3% | Aug 10, 2011 |
64This week | CVE-2010-3552Weaponized | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to asun · jre | Critical10.0 | — | 80.7% | Oct 19, 2010 |
64This week | CVE-2010-0361Weaponized | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attsun · java system web server · CWE-119 | Critical10.0 | — | 80.4% | Jan 20, 2010 |
62This week | CVE-2003-0466Proof of concept | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Critical9.8 | — | 78.1% | Aug 27, 2003 |
62This week | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Critical10.0 | — | 72.6% | Mar 7, 2003 |
62This week | CVE-2001-0236Proof of concept | Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"sun · solaris | Critical10.0 | — | 72.0% | May 3, 2001 |
61This week | CVE-2010-0886Weaponized | Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1sun · jre | Critical10.0 | — | 69.9% | Apr 20, 2010 |
61This week | CVE-2008-4556Weaponized | Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers sun · solaris · CWE-119 | Critical10.0 | — | 69.9% | Oct 14, 2008 |
61This week | CVE-2012-1533Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earloracle · jdk | Critical10.0 | — | 69.0% | Oct 16, 2012 |
61This week | CVE-2008-0960Proof of concept | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Jnet-snmp · net snmp · CWE-287 | Critical10.0 | — | 68.8% | Jun 10, 2008 |
60This week | CVE-2003-0694Weaponized | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Critical10.0 | — | 66.2% | Oct 6, 2003 |
59Plan | CVE-2009-3867Weaponized | Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before sun · jdk · CWE-119 | Critical9.3 | — | 73.4% | Nov 5, 2009 |
59Plan | CVE-2001-0779Proof of concept | Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.sun · solaris | Critical10.0 | — | 62.2% | Oct 18, 2001 |
- CVE-2013-246599Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jreJun 18, 2013
- CVE-2012-050798Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
CriticalCVSS 9.8KEVWeaponizedEPSS 98%oracle · jreJun 7, 2012
- CVE-2007-088269This week
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "
CriticalCVSS 10.0WeaponizedEPSS 98%sun · sunosFeb 12, 2007
- CVE-2001-079768This week
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
CriticalCVSS 10.0WeaponizedEPSS 95%sgi · irixDec 12, 2001
- CVE-2003-072267This week
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstic
CriticalCVSS 10.0WeaponizedEPSS 89%sun · solarisSep 22, 2003
- CVE-2011-211066This week
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attack
CriticalCVSS 10.0WeaponizedEPSS 86%adobe · flash playerJun 16, 2011
- CVE-2013-149366This week
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Upd
CriticalCVSS 10.0WeaponizedEPSS 86%oracle · jreMar 5, 2013
- CVE-2008-535366This week
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2
CriticalCVSS 10.0WeaponizedEPSS 86%sun · jdkDec 5, 2008
- CVE-2003-020165This week
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
CriticalCVSS 10.0WeaponizedEPSS 85%samba · sambaMay 5, 2003
- CVE-2010-356365This week
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect
CriticalCVSS 10.0WeaponizedEPSS 84%sun · jreOct 19, 2010
- CVE-2001-158365This week
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control
CriticalCVSS 10.0WeaponizedEPSS 83%sun · sunosDec 31, 2001
- CVE-2010-445265This week
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23
CriticalCVSS 10.0WeaponizedEPSS 83%sun · jreFeb 17, 2011
- CVE-2011-214065This week
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 o
CriticalCVSS 10.0WeaponizedEPSS 82%adobe · flash playerAug 10, 2011
- CVE-2010-355264This week
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to a
CriticalCVSS 10.0WeaponizedEPSS 81%sun · jreOct 19, 2010
- CVE-2010-036164This week
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote att
CriticalCVSS 10.0WeaponizedEPSS 80%sun · java system web serverJan 20, 2010
- CVE-2003-046662This week
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
CriticalCVSS 9.8Proof of conceptEPSS 78%redhat · wu ftpdAug 27, 2003
- CVE-2002-133762This week
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
CriticalCVSS 10.0Proof of conceptEPSS 73%sendmail · sendmailMar 7, 2003
- CVE-2001-023662This week
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"
CriticalCVSS 10.0Proof of conceptEPSS 72%sun · solarisMay 3, 2001
- CVE-2010-088661This week
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1
CriticalCVSS 10.0WeaponizedEPSS 70%sun · jreApr 20, 2010
- CVE-2008-455661This week
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers
CriticalCVSS 10.0WeaponizedEPSS 70%sun · solarisOct 14, 2008
- CVE-2012-153361This week
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earl
CriticalCVSS 10.0WeaponizedEPSS 69%oracle · jdkOct 16, 2012
- CVE-2008-096061This week
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J
CriticalCVSS 10.0Proof of conceptEPSS 69%net-snmp · net snmpJun 10, 2008
- CVE-2003-069460This week
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
CriticalCVSS 10.0WeaponizedEPSS 66%sendmail · advanced message serverOct 6, 2003
- CVE-2009-386759Plan
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before
CriticalCVSS 9.3WeaponizedEPSS 73%sun · jdkNov 5, 2009
- CVE-2001-077959Plan
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
CriticalCVSS 10.0Proof of conceptEPSS 62%sun · solarisOct 18, 2001