Vulnerabilities > SUN > RAY Server Software > 4.0

DATE CVE VULNERABILITY TITLE RISK
2009-12-11 CVE-2009-4295 Cryptographic Issues vulnerability in SUN RAY Server Software 4.0/4.1
Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic.
network
low complexity
sun CWE-310
7.8
2009-12-11 CVE-2009-4294 Remote Code Execution vulnerability in Sun Ray Server Authentication Manager
Unspecified vulnerability in the Authentication Manager (aka utauthd) in Sun Ray Server Software 4.0 and 4.1 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.
network
low complexity
sun
critical
10.0
2009-07-16 CVE-2009-2491 Unspecified vulnerability in SUN RAY Server Software 4.0
The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "resource leaks."
local
sun
4.4
2009-07-16 CVE-2009-2490 Unspecified vulnerability in SUN RAY Server Software 4.0
Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to "resource leaks."
local
sun
1.9
2009-07-16 CVE-2009-2489 Unspecified vulnerability in SUN RAY Server Software 4.0
Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.
local
low complexity
sun
2.1
2008-12-11 CVE-2008-5423 Information Exposure vulnerability in SUN RAY Server Software and RAY Windows Connector
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.
local
low complexity
sun novell redhat CWE-200
4.3
2008-12-11 CVE-2008-5422 Permissions, Privileges, and Access Controls vulnerability in SUN RAY Server Software
Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors.
network
low complexity
sun novell redhat CWE-264
7.5
2008-05-08 CVE-2008-2112 Privilege Escalation vulnerability in SUN RAY Server Software 4.0
Unspecified vulnerability in Sun Ray Kiosk Mode 4.0 allows local and remote authenticated Sun Ray administrators to gain root privileges via unknown vectors related to utconfig.
network
novell redhat sun
8.5