Vulnerabilities > SUN

DATE CVE VULNERABILITY TITLE RISK
2007-08-17 CVE-2007-4395 Remote Privilege Escalation vulnerability in SUN Sunos 5.8
Multiple unspecified vulnerabilities in the Role Based Access Control (RBAC) functionality in Sun Solaris 8 allow remote attackers who know the password for a role to gain privileges via that role.
network
high complexity
sun
7.6
2007-08-17 CVE-2007-4381 Remote Privilege Escalation vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.
network
sun
critical
9.3
2007-08-13 CVE-2007-4310 Remote Security vulnerability in SUN Sunos 5.7/5.8/5.9
The finger daemon (in.fingerd) in Sun Solaris 7 through 9 allows remote attackers to list all accounts that have certain nonstandard GECOS fields via a request composed of a single digit, as demonstrated by a "finger 9@host" command, a different vulnerability than CVE-2001-1503.
network
sun
4.3
2007-08-09 CVE-2007-4289 Remote Security vulnerability in SUN Java System Portal Server 7.0
Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3715.
network
sun
6.8
2007-08-07 CVE-2007-4164 HTTP Redirect vulnerability in Sun Java System Web Server 6.1/7.0
CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.
network
low complexity
sun
7.5
2007-08-01 CVE-2007-4126 Local Denial of Service vulnerability in SUN Solaris 10.0
Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.
local
sun
1.5
2007-07-30 CVE-2007-4070 Information Disclosure vulnerability in SUN Solaris 10.0/8.0/9.0
Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.
local
low complexity
sun
4.9
2007-07-26 CVE-2007-4025 Unspecified vulnerability in SUN Java System Application Server 8.1/8.2/9.0
Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.
network
sun
4.3
2007-07-21 CVE-2007-3922 Unspecified vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.
network
sun
6.8
2007-07-15 CVE-2007-3794 Buffer Overflow vulnerability in Multiple Hitachi Products GIF Image
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.
network
low complexity
microsoft hitachi linux hp ibm sun
critical
10.0