Search: "sun"

1458 CVEs found

CVE-2002-1140
5.0 MEDIUM

The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malfor...

Published: 2002-10-11
Products: 1
Vendors:
microsoft
CVE-2002-1141
5.0 MEDIUM

An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of serv...

Published: 2002-10-11
Products: 1
Vendors:
microsoft

The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with worl...

Published: 2002-10-29
Products: 2
Vendors:
sun
CVE-2002-1265
5.0 MEDIUM

The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (han...

Published: 2002-11-12
Products: 59
Vendors:
gnu sgi apple
CVE-2002-1361
10.0 HIGH

overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the emai...

Published: 2002-12-23
Products: 1
Vendors:
sun
CVE-2002-1763
4.6 MEDIUM

The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.

Published: 2002-12-31
Products: 1
Vendors:
sun

pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to ele...

Published: 2002-12-31
Products: 4
Vendors:
sun

Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.

Published: 2002-12-31
Products: 8
Vendors:
sun

Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.

Published: 2002-12-31
Products: 1
Vendors:
sun
CVE-2002-2072
5.0 MEDIUM

java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged ...

Published: 2002-12-31
Products: 2
Vendors:
sun

Unknown vulnerability in Sun Solaris 8.0 allows local users to cause a denial of service (kernel panic) via a program that uses /dev/poll, triggering a NULL pointer dereference.

Published: 2002-12-31
Products: 2
Vendors:
sun
CVE-2002-2248
10.0 HIGH

Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset ...

Published: 2002-12-31
Products: 14
Vendors:
netscape

Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remo...

Published: 2002-12-31
Products: 1
Vendors:
sun
CVE-2002-2327
4.9 MEDIUM

Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties.

Published: 2002-12-31
Products: 4
Vendors:
sun
CVE-2002-2374
10.0 HIGH

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

Published: 2002-12-31
Products: 1
Vendors:
sun
CVE-2002-2425
10.0 HIGH

Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

Published: 2002-12-31
Products: 5
Vendors:
sun
CVE-2003-0027
5.0 MEDIUM

Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.

Published: 2003-02-07
Products: 10
Vendors:
sun

Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.

Published: 2003-03-18
Products: 2
Vendors:
sun

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allo...

Published: 2003-03-25
Products: 165
Vendors:
cray hp sun openafs gnu +5 more
CVE-2002-1525
5.0 MEDIUM

Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (...

Published: 2003-04-02
Products: 2
Vendors:
astaware sun