Vulnerabilities > SUN

DATE CVE VULNERABILITY TITLE RISK
2007-12-04 CVE-2007-6225 Local Denial of Service vulnerability in SUN Solaris 10
Unspecified vulnerability in Sun Solaris 10, when 64bit mode is used on the x86 platform, allows local users in a Linux (lx) branded zone to cause a denial of service (panic) via unspecified vectors.
local
low complexity
sun
4.9
2007-12-04 CVE-2007-6216 Race Condition vulnerability in SUN Solaris and Sunos
Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.
local
sun CWE-362
4.7
2007-11-30 CVE-2007-6180 Race Condition vulnerability in SUN Solaris 10.0/8.0/9.0
Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via unspecified vectors.
7.6
2007-11-14 CVE-2007-3880 USE of Externally-Controlled Format String vulnerability in SUN NET Connect Software 3.2.3/3.2.4
Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.
local
low complexity
sun CWE-134
7.2
2007-11-10 CVE-2007-5921 Local Denial of Service vulnerability in Sun Solaris Volume Manager
Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris 9 and 10 allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2004-1346.
local
sun
4.7
2007-10-30 CVE-2007-5726 Remote Denial of Service vulnerability in SUN Solaris 10.0
Unspecified vulnerability in the Stream Control Transmission Protocol (sctp) functionality in Sun Solaris 10, when at least one SCTP socket is in the LISTEN state, allows remote attackers to cause a denial of service (panic) via unspecified vectors related to "INIT processing."
network
low complexity
sun
6.8
2007-10-30 CVE-2007-5717 Remote Arbitrary Command Execution vulnerability in Sun Fire X2100 M2 And X2200 M2 ELOM
Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) on x86 before firmware 2.70 allows remote attackers to execute arbitrary commands as root on the Service Processor (SP) via unspecified vectors, a different vulnerability than CVE-2007-5170.
network
low complexity
sun
critical
10.0
2007-10-30 CVE-2007-5716 Local Denial Of Service vulnerability in SUN Solaris 10.0
Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.
network
low complexity
sun
7.8
2007-10-29 CVE-2007-5689 Remote Privilege Escalation vulnerability in SUN Jdk, JRE and SDK
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
network
low complexity
sun
critical
10.0
2007-10-23 CVE-2007-5632 Local Denial of Service vulnerability in SUN Solaris 10.0/8.0/9.0
Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions.
local
low complexity
sun
4.9