Vulnerabilities > SUN > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-07-09 CVE-2008-3108 Buffer Errors vulnerability in SUN Jdk, JRE and SDK
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.
network
low complexity
sun CWE-119
critical
10.0
2008-07-09 CVE-2008-3107 Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
network
low complexity
sun CWE-264
critical
10.0
2008-07-09 CVE-2008-3103 Permissions, Privileges, and Access Controls vulnerability in SUN JDK and JRE
Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to "perform unauthorized operations" via unspecified vectors.
network
sun CWE-264
critical
9.3
2008-06-16 CVE-2008-2705 Improper Authentication vulnerability in SUN Java System Access Manager 7.1
Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors.
network
sun CWE-287
critical
9.3
2008-06-10 CVE-2008-0960 Improper Authentication vulnerability in Juniper Session and Resource Control and SRC PE
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
network
low complexity
cisco ecos-sourceware net-snmp sun ingate juniper CWE-287
critical
10.0
2008-06-04 CVE-2008-2404 Buffer Errors vulnerability in SUN Java ASP Server 4.0
Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field.
network
low complexity
sun CWE-119
critical
10.0
2008-06-04 CVE-2008-2403 Path Traversal vulnerability in SUN Java ASP Server 4.0/4.0.1
Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a ..
network
low complexity
sun CWE-22
critical
10.0
2008-05-12 CVE-2008-2144 Remote Code Execution vulnerability in SUN Sunos 5.10/5.8/5.9
Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.
network
low complexity
sun
critical
10.0
2008-03-18 CVE-2008-1369 Permissions, Privileges, and Access Controls vulnerability in SUN Sunos 5.10
A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root logins in a manner unintended by the vendor, which allows remote attackers to gain privileges via unspecified vectors.
network
low complexity
sun CWE-264
critical
10.0
2008-03-06 CVE-2008-1195 7PK - Security Features vulnerability in multiple products
Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.
network
sun canonical CWE-254
critical
9.3