Vulnerabilities > SUN

DATE CVE VULNERABILITY TITLE RISK
2006-05-17 CVE-2006-2426 Remote Denial Of Service vulnerability in SUN Jdk, JRE and SDK
Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.
network
low complexity
sun
6.4
2006-04-27 CVE-2006-2064 Local Privilege Escalation vulnerability in SUN Solaris 10.0
Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain privileges or cause a denial of service (application failure) via unknown attack vectors that involve the getpwnam family of non-reentrant functions.
local
low complexity
sun
4.6
2006-04-19 CVE-2006-1830 Local Privilege Escalation vulnerability in SUN Java Studio Enterprise 8
Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.
local
high complexity
sun
3.7
2006-04-13 CVE-2006-1782 Unspecified vulnerability in SUN Solaris and Sunos
Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.
local
low complexity
sun
2.1
2006-04-13 CVE-2006-1780 Local Denial of Service vulnerability in Sun Solaris SH(1)
The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.
local
low complexity
sun
2.1
2006-04-04 CVE-2006-1601 Unspecified vulnerability in SUN Cluster 3.1
Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors.
local
low complexity
sun
1.7
2006-03-30 CVE-2006-1506 Local Security vulnerability in Grid Engine
Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.
local
low complexity
sun
7.2
2006-03-21 CVE-2006-0745 Local Privilege Escalation vulnerability in X.Org X Window Server
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
local
low complexity
x-org mandrakesoft redhat sun suse
7.2
2006-03-09 CVE-2006-1092 Local Denial Of Service vulnerability in Sun Solaris Proc Filesystem Pagedata Subsystem
Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to allocate a large amount of system memory that does not get freed.
local
low complexity
sun
2.1
2006-02-27 CVE-2006-0901 Local Denial Of Service vulnerability in Sun Solaris HSFS Filesystem
Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.
local
low complexity
sun
7.2