Vulnerabilities > SUN > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-10-21 CVE-2008-4619 Unspecified vulnerability in SUN Sunos 5.9
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function.
network
low complexity
sun
critical
10.0
2008-10-14 CVE-2008-4556 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in SUN Solaris 8/9
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.
network
low complexity
sun CWE-119
critical
10.0
2008-10-13 CVE-2008-4541 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in SUN Java System web Proxy Server
Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.7 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.
network
low complexity
sun CWE-119
critical
10.0
2008-08-08 CVE-2008-3553 Permissions, Privileges, and Access Controls vulnerability in SUN J2Me
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 3-10." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information.
network
low complexity
sun nokia CWE-264
critical
10.0
2008-08-08 CVE-2008-3551 Security-Bypass vulnerability in SUN Java Platform Micro Edition and Wireless Toolkit
Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
sun
critical
10.0
2008-08-08 CVE-2008-0965 USE of Externally-Controlled Format String vulnerability in SUN Opensolaris, Solaris and Sunos
Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.
network
sun CWE-134
critical
9.3
2008-08-08 CVE-2008-0964 Buffer Errors vulnerability in SUN Opensolaris, Solaris and Sunos
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.
network
sun CWE-119
critical
9.3
2008-07-09 CVE-2008-3113 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3112 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3111 Improper Input Validation vulnerability in SUN Jdk, JRE and SDK
Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.
network
low complexity
sun CWE-20
critical
10.0