Записи sun
1 711 опубликованных записей вендора sun.
Профиль для исследователя
- Попали в KEV
- 2 · 0,1 %
- С эксплойтом
- 37 · 2,2 %
- Pre-auth RCE
- 202
- С записью об исправлении
- 28,4 %
- Медиана: публикация → KEV
- 3381 дн.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls99
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer72
- CWE-399 Resource Management Errors47
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-20 Improper Input Validation33
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 711 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2013-2465Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Критическая9,8 | KEV | 98,8 % | 18 июн. 2013 г. |
98Срочно | CVE-2012-0507Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Критическая9,8 | KEV | 98,1 % | 7 июн. 2012 г. |
69На этой неделе | CVE-2007-0882Готовый эксплойт | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "sun · sunos · CWE-88 | Критическая10,0 | — | 98,0 % | 12 февр. 2007 г. |
68На этой неделе | CVE-2001-0797Готовый эксплойт | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Критическая10,0 | — | 94,7 % | 12 дек. 2001 г. |
67На этой неделе | CVE-2003-0722Готовый эксплойт | The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solsticsun · solaris | Критическая10,0 | — | 88,8 % | 22 сент. 2003 г. |
66На этой неделе | CVE-2011-2110Готовый эксплойт | Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackadobe · flash player · CWE-119 | Критическая10,0 | — | 86,4 % | 16 июн. 2011 г. |
66На этой неделе | CVE-2013-1493Готовый эксплойт | The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Updoracle · jre · CWE-119 | Критическая10,0 | — | 86,2 % | 5 мар. 2013 г. |
66На этой неделе | CVE-2008-5353Готовый эксплойт | The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2sun · jdk | Критическая10,0 | — | 85,8 % | 5 дек. 2008 г. |
65На этой неделе | CVE-2003-0201Готовый эксплойт | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Критическая10,0 | — | 84,5 % | 5 мая 2003 г. |
65На этой неделе | CVE-2010-3563Готовый эксплойт | Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect sun · jre | Критическая10,0 | — | 84,3 % | 19 окт. 2010 г. |
65На этой неделе | CVE-2001-1583Готовый эксплойт | lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control sun · sunos · CWE-78 | Критическая10,0 | — | 83,4 % | 31 дек. 2001 г. |
65На этой неделе | CVE-2010-4452Готовый эксплойт | Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 sun · jre | Критическая10,0 | — | 82,8 % | 17 февр. 2011 г. |
65На этой неделе | CVE-2011-2140Готовый эксплойт | Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 oadobe · flash player · CWE-119 | Критическая10,0 | — | 82,3 % | 10 авг. 2011 г. |
64На этой неделе | CVE-2010-3552Готовый эксплойт | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to asun · jre | Критическая10,0 | — | 80,7 % | 19 окт. 2010 г. |
64На этой неделе | CVE-2010-0361Готовый эксплойт | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attsun · java system web server · CWE-119 | Критическая10,0 | — | 80,4 % | 20 янв. 2010 г. |
62На этой неделе | CVE-2003-0466Proof of concept | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Критическая9,8 | — | 78,1 % | 27 авг. 2003 г. |
62На этой неделе | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Критическая10,0 | — | 72,6 % | 7 мар. 2003 г. |
62На этой неделе | CVE-2001-0236Proof of concept | Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"sun · solaris | Критическая10,0 | — | 72,0 % | 3 мая 2001 г. |
61На этой неделе | CVE-2010-0886Готовый эксплойт | Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1sun · jre | Критическая10,0 | — | 69,9 % | 20 апр. 2010 г. |
61На этой неделе | CVE-2008-4556Готовый эксплойт | Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers sun · solaris · CWE-119 | Критическая10,0 | — | 69,9 % | 14 окт. 2008 г. |
61На этой неделе | CVE-2012-1533Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earloracle · jdk | Критическая10,0 | — | 69,0 % | 16 окт. 2012 г. |
61На этой неделе | CVE-2008-0960Proof of concept | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Jnet-snmp · net snmp · CWE-287 | Критическая10,0 | — | 68,8 % | 10 июн. 2008 г. |
60На этой неделе | CVE-2003-0694Готовый эксплойт | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Критическая10,0 | — | 66,2 % | 6 окт. 2003 г. |
59В плане | CVE-2009-3867Готовый эксплойт | Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before sun · jdk · CWE-119 | Критическая9,3 | — | 73,4 % | 5 нояб. 2009 г. |
59В плане | CVE-2001-0779Proof of concept | Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.sun · solaris | Критическая10,0 | — | 62,2 % | 18 окт. 2001 г. |
- CVE-2013-246599Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jre18 июн. 2013 г.
- CVE-2012-050798Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %oracle · jre7 июн. 2012 г.
- CVE-2007-088269На этой неделе
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "
КритическаяCVSS 10,0Готовый эксплойтEPSS 98 %sun · sunos12 февр. 2007 г.
- CVE-2001-079768На этой неделе
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %sgi · irix12 дек. 2001 г.
- CVE-2003-072267На этой неделе
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstic
КритическаяCVSS 10,0Готовый эксплойтEPSS 89 %sun · solaris22 сент. 2003 г.
- CVE-2011-211066На этой неделе
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attack
КритическаяCVSS 10,0Готовый эксплойтEPSS 86 %adobe · flash player16 июн. 2011 г.
- CVE-2013-149366На этой неделе
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Upd
КритическаяCVSS 10,0Готовый эксплойтEPSS 86 %oracle · jre5 мар. 2013 г.
- CVE-2008-535366На этой неделе
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2
КритическаяCVSS 10,0Готовый эксплойтEPSS 86 %sun · jdk5 дек. 2008 г.
- CVE-2003-020165На этой неделе
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
КритическаяCVSS 10,0Готовый эксплойтEPSS 85 %samba · samba5 мая 2003 г.
- CVE-2010-356365На этой неделе
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect
КритическаяCVSS 10,0Готовый эксплойтEPSS 84 %sun · jre19 окт. 2010 г.
- CVE-2001-158365На этой неделе
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control
КритическаяCVSS 10,0Готовый эксплойтEPSS 83 %sun · sunos31 дек. 2001 г.
- CVE-2010-445265На этой неделе
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23
КритическаяCVSS 10,0Готовый эксплойтEPSS 83 %sun · jre17 февр. 2011 г.
- CVE-2011-214065На этой неделе
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 o
КритическаяCVSS 10,0Готовый эксплойтEPSS 82 %adobe · flash player10 авг. 2011 г.
- CVE-2010-355264На этой неделе
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to a
КритическаяCVSS 10,0Готовый эксплойтEPSS 81 %sun · jre19 окт. 2010 г.
- CVE-2010-036164На этой неделе
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote att
КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %sun · java system web server20 янв. 2010 г.
- CVE-2003-046662На этой неделе
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
КритическаяCVSS 9,8Proof of conceptEPSS 78 %redhat · wu ftpd27 авг. 2003 г.
- CVE-2002-133762На этой неделе
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
КритическаяCVSS 10,0Proof of conceptEPSS 73 %sendmail · sendmail7 мар. 2003 г.
- CVE-2001-023662На этой неделе
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"
КритическаяCVSS 10,0Proof of conceptEPSS 72 %sun · solaris3 мая 2001 г.
- CVE-2010-088661На этой неделе
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1
КритическаяCVSS 10,0Готовый эксплойтEPSS 70 %sun · jre20 апр. 2010 г.
- CVE-2008-455661На этой неделе
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers
КритическаяCVSS 10,0Готовый эксплойтEPSS 70 %sun · solaris14 окт. 2008 г.
- CVE-2012-153361На этой неделе
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earl
КритическаяCVSS 10,0Готовый эксплойтEPSS 69 %oracle · jdk16 окт. 2012 г.
- CVE-2008-096061На этой неделе
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J
КритическаяCVSS 10,0Proof of conceptEPSS 69 %net-snmp · net snmp10 июн. 2008 г.
- CVE-2003-069460На этой неделе
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %sendmail · advanced message server6 окт. 2003 г.
- CVE-2009-386759В плане
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before
КритическаяCVSS 9,3Готовый эксплойтEPSS 73 %sun · jdk5 нояб. 2009 г.
- CVE-2001-077959В плане
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
КритическаяCVSS 10,0Proof of conceptEPSS 62 %sun · solaris18 окт. 2001 г.