sun kayıtları
sun üreticisine ait 1.711 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,1
- Silahlaştırılmış
- 37 · %2,2
- Pre-auth RCE
- 202
- Düzeltme kaydı olan
- %28,4
- Yayından KEV’e ortanca
- 3381 gün
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls99
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer72
- CWE-399 Resource Management Errors47
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')41
- CWE-20 Improper Input Validation33
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor27
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
1.711 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2013-2465Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Kritik9,8 | KEV | %98,8 | 18 Haz 2013 |
98Hemen | CVE-2012-0507Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,oracle · jre · CWE-843 | Kritik9,8 | KEV | %98,1 | 7 Haz 2012 |
69Bu hafta | CVE-2007-0882Silahlaştırılmış | Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "sun · sunos · CWE-88 | Kritik10,0 | — | %98,0 | 12 Şub 2007 |
68Bu hafta | CVE-2001-0797Silahlaştırılmış | Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbesgi · irix | Kritik10,0 | — | %94,7 | 12 Ara 2001 |
67Bu hafta | CVE-2003-0722Silahlaştırılmış | The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solsticsun · solaris | Kritik10,0 | — | %88,8 | 22 Eyl 2003 |
66Bu hafta | CVE-2011-2110Silahlaştırılmış | Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackadobe · flash player · CWE-119 | Kritik10,0 | — | %86,4 | 16 Haz 2011 |
66Bu hafta | CVE-2013-1493Silahlaştırılmış | The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Updoracle · jre · CWE-119 | Kritik10,0 | — | %86,2 | 5 Mar 2013 |
66Bu hafta | CVE-2008-5353Silahlaştırılmış | The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2sun · jdk | Kritik10,0 | — | %85,8 | 5 Ara 2008 |
65Bu hafta | CVE-2003-0201Silahlaştırılmış | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG samba · samba | Kritik10,0 | — | %84,5 | 5 May 2003 |
65Bu hafta | CVE-2010-3563Silahlaştırılmış | Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect sun · jre | Kritik10,0 | — | %84,3 | 19 Eki 2010 |
65Bu hafta | CVE-2001-1583Silahlaştırılmış | lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control sun · sunos · CWE-78 | Kritik10,0 | — | %83,4 | 31 Ara 2001 |
65Bu hafta | CVE-2010-4452Silahlaştırılmış | Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 sun · jre | Kritik10,0 | — | %82,8 | 17 Şub 2011 |
65Bu hafta | CVE-2011-2140Silahlaştırılmış | Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 oadobe · flash player · CWE-119 | Kritik10,0 | — | %82,3 | 10 Ağu 2011 |
64Bu hafta | CVE-2010-3552Silahlaştırılmış | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to asun · jre | Kritik10,0 | — | %80,7 | 19 Eki 2010 |
64Bu hafta | CVE-2010-0361Silahlaştırılmış | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attsun · java system web server · CWE-119 | Kritik10,0 | — | %80,4 | 20 Oca 2010 |
62Bu hafta | CVE-2003-0466Kavram kanıtı | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Kritik9,8 | — | %78,1 | 27 Ağu 2003 |
62Bu hafta | CVE-2002-1337Kavram kanıtı | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Kritik10,0 | — | %72,6 | 7 Mar 2003 |
62Bu hafta | CVE-2001-0236Kavram kanıtı | Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"sun · solaris | Kritik10,0 | — | %72,0 | 3 May 2001 |
61Bu hafta | CVE-2010-0886Silahlaştırılmış | Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1sun · jre | Kritik10,0 | — | %69,9 | 20 Nis 2010 |
61Bu hafta | CVE-2008-4556Silahlaştırılmış | Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers sun · solaris · CWE-119 | Kritik10,0 | — | %69,9 | 14 Eki 2008 |
61Bu hafta | CVE-2012-1533Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earloracle · jdk | Kritik10,0 | — | %69,0 | 16 Eki 2012 |
61Bu hafta | CVE-2008-0960Kavram kanıtı | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Jnet-snmp · net snmp · CWE-287 | Kritik10,0 | — | %68,8 | 10 Haz 2008 |
60Bu hafta | CVE-2003-0694Silahlaştırılmış | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Kritik10,0 | — | %66,2 | 6 Eki 2003 |
59Planlayın | CVE-2009-3867Silahlaştırılmış | Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before sun · jdk · CWE-119 | Kritik9,3 | — | %73,4 | 5 Kas 2009 |
59Planlayın | CVE-2001-0779Kavram kanıtı | Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.sun · solaris | Kritik10,0 | — | %62,2 | 18 Eki 2001 |
- CVE-2013-246599Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99oracle · jre18 Haz 2013
- CVE-2012-050798Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98oracle · jre7 Haz 2012
- CVE-2007-088269Bu hafta
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "
KritikCVSS 10,0SilahlaştırılmışEPSS %98sun · sunos12 Şub 2007
- CVE-2001-079768Bu hafta
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large numbe
KritikCVSS 10,0SilahlaştırılmışEPSS %95sgi · irix12 Ara 2001
- CVE-2003-072267Bu hafta
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstic
KritikCVSS 10,0SilahlaştırılmışEPSS %89sun · solaris22 Eyl 2003
- CVE-2011-211066Bu hafta
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attack
KritikCVSS 10,0SilahlaştırılmışEPSS %86adobe · flash player16 Haz 2011
- CVE-2013-149366Bu hafta
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Upd
KritikCVSS 10,0SilahlaştırılmışEPSS %86oracle · jre5 Mar 2013
- CVE-2008-535366Bu hafta
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2
KritikCVSS 10,0SilahlaştırılmışEPSS %86sun · jdk5 Ara 2008
- CVE-2003-020165Bu hafta
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG
KritikCVSS 10,0SilahlaştırılmışEPSS %85samba · samba5 May 2003
- CVE-2010-356365Bu hafta
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect
KritikCVSS 10,0SilahlaştırılmışEPSS %84sun · jre19 Eki 2010
- CVE-2001-158365Bu hafta
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control
KritikCVSS 10,0SilahlaştırılmışEPSS %83sun · sunos31 Ara 2001
- CVE-2010-445265Bu hafta
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23
KritikCVSS 10,0SilahlaştırılmışEPSS %83sun · jre17 Şub 2011
- CVE-2011-214065Bu hafta
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 o
KritikCVSS 10,0SilahlaştırılmışEPSS %82adobe · flash player10 Ağu 2011
- CVE-2010-355264Bu hafta
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to a
KritikCVSS 10,0SilahlaştırılmışEPSS %81sun · jre19 Eki 2010
- CVE-2010-036164Bu hafta
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote att
KritikCVSS 10,0SilahlaştırılmışEPSS %80sun · java system web server20 Oca 2010
- CVE-2003-046662Bu hafta
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
KritikCVSS 9,8Kavram kanıtıEPSS %78redhat · wu ftpd27 Ağu 2003
- CVE-2002-133762Bu hafta
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
KritikCVSS 10,0Kavram kanıtıEPSS %73sendmail · sendmail7 Mar 2003
- CVE-2001-023662Bu hafta
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication"
KritikCVSS 10,0Kavram kanıtıEPSS %72sun · solaris3 May 2001
- CVE-2010-088661Bu hafta
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 1
KritikCVSS 10,0SilahlaştırılmışEPSS %70sun · jre20 Nis 2010
- CVE-2008-455661Bu hafta
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers
KritikCVSS 10,0SilahlaştırılmışEPSS %70sun · solaris14 Eki 2008
- CVE-2012-153361Bu hafta
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earl
KritikCVSS 10,0SilahlaştırılmışEPSS %69oracle · jdk16 Eki 2012
- CVE-2008-096061Bu hafta
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J
KritikCVSS 10,0Kavram kanıtıEPSS %69net-snmp · net snmp10 Haz 2008
- CVE-2003-069460Bu hafta
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
KritikCVSS 10,0SilahlaştırılmışEPSS %66sendmail · advanced message server6 Eki 2003
- CVE-2009-386759Planlayın
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before
KritikCVSS 9,3SilahlaştırılmışEPSS %73sun · jdk5 Kas 2009
- CVE-2001-077959Planlayın
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.
KritikCVSS 10,0Kavram kanıtıEPSS %62sun · solaris18 Eki 2001