Vulnerabilities > SUN

DATE CVE VULNERABILITY TITLE RISK
2008-09-22 CVE-2008-4160 Resource Management Errors vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.
local
sun CWE-399
4.7
2008-09-19 CVE-2008-4131 Permissions, Privileges, and Access Controls vulnerability in SUN Solaris 10/8/9
Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.
local
low complexity
sun CWE-264
7.2
2008-09-18 CVE-2008-4117 Remote Denial of Service vulnerability in SUN Management Center 3.6.1/4.0
Unspecified vulnerability in a web page in the PRM module in Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
network
low complexity
sun
7.8
2008-09-02 CVE-2008-3875 Permissions, Privileges, and Access Controls vulnerability in SUN Opensolaris and Solaris
The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.
local
low complexity
sun CWE-264
7.2
2008-08-27 CVE-2008-3839 Local Denial of Service vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the NFS module in the kernel in Sun Solaris 10 and OpenSolaris snv_59 through snv_87, when configured as an NFS server without the nodevices option, allows local users to cause a denial of service (panic) via unspecified vectors.
local
sun
4.7
2008-08-27 CVE-2008-3838 Improper Input Validation vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.
local
low complexity
sun CWE-20
7.2
2008-08-14 CVE-2008-3683 Denial of Service vulnerability in Sun Java System Web Proxy Server FTP Subsystem
Unspecified vulnerability in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.5 before SP6 allows remote attackers to cause a denial of service (failure to accept connections) via unknown vectors, probably related to exhaustion of file descriptors.
network
low complexity
sun
5.0
2008-08-13 CVE-2008-3666 Local Denial of Service vulnerability in SUN Opensolaris, Solaris and Sunos
Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.
network
sun
7.1
2008-08-08 CVE-2008-3553 Permissions, Privileges, and Access Controls vulnerability in SUN J2Me
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 3-10." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information.
network
low complexity
sun nokia CWE-264
critical
10.0
2008-08-08 CVE-2008-3551 Security-Bypass vulnerability in SUN Java Platform Micro Edition and Wireless Toolkit
Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
sun
critical
10.0