Vulnerabilities > SUN

DATE CVE VULNERABILITY TITLE RISK
2008-12-19 CVE-2008-5684 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).
network
low complexity
sun CWE-399
5.0
2008-12-17 CVE-2008-5662 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in SUN Java Wireless Toolkit FOR Cldc
Multiple buffer overflows in Sun Java Wireless Toolkit (WTK) for CLDC 2.5.2 and earlier allow downloaded programs to execute arbitrary code via unknown vectors.
network
sun CWE-119
critical
9.3
2008-12-17 CVE-2008-5661 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.
network
high complexity
sun CWE-399
5.4
2008-12-12 CVE-2008-5550 URI Redirection vulnerability in SUN Java web Console, Solaris and Sunos
Open redirect vulnerability in console/faces/jsp/login/BeginLogin.jsp in Sun Java Web Console 3.0.2 through 3.0.5 and Solaris 10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the redirect_url parameter.
network
sun
4.3
2008-12-12 CVE-2008-5549 Permissions, Privileges, and Access Controls vulnerability in SUN Java System Portal Server 7.1/7.2
Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local files and read the product's configuration information via unknown vectors related to "access to secure files by ThemeServlet."
network
low complexity
sun CWE-264
5.0
2008-12-11 CVE-2008-5423 Information Exposure vulnerability in SUN RAY Server Software and RAY Windows Connector
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.
local
low complexity
sun novell redhat CWE-200
4.3
2008-12-11 CVE-2008-5422 Permissions, Privileges, and Access Controls vulnerability in SUN RAY Server Software
Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors.
network
low complexity
sun novell redhat CWE-264
7.5
2008-12-10 CVE-2008-5410 Cryptographic Issues vulnerability in SUN Solaris 10.0
The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which allows context-dependent attackers to cause a denial of service (failed cryptographic operations) via unspecified vectors, related to the (1) RSA_sign and (2) RSA_verify functions.
network
low complexity
sun CWE-310
7.8
2008-12-05 CVE-2008-5360 Multiple Security vulnerability in SUN Jdk, JRE and SDK
Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.
network
low complexity
sun
6.4
2008-12-05 CVE-2008-5359 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.
network
sun CWE-119
critical
9.3