← Back

Ray Server Software

ray_server_software

Vendor: Sun • 15 CVEs

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
1Ray Server Software
Apr 23, 2026
Dec 14, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate att...Show more
Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device.Show less
1Sun
1Ray Server Software
Apr 23, 2026
Dec 11, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information b...Show more
Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic.Show less
1Sun
1Ray Server Software
Apr 23, 2026
Dec 11, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the Authentication Manager (aka utauthd) in Sun Ray Server Software 4.0 and 4.1 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.
1Sun
1Ray Server Software
Apr 23, 2026
Jul 16, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "resource leaks."
1Sun
1Ray Server Software
Apr 23, 2026
Jul 16, 2009
N/A· v4
N/A· v3
1.9 LOW· v2
Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileg...Show more
Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to "resource leaks."Show less
1Sun
1Ray Server Software
Apr 23, 2026
Jul 16, 2009
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.
1Sun
2Ray Server Software
Ray Windows Connector
Apr 23, 2026
Dec 11, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain...Show more
Sun Sun Ray Server Software 3.x and 4.0 and Sun Ray Windows Connector 1.1 and 2.0 expose the LDAP password during a configuration step, which allows local users to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors related to the utconfig component of the Server Software and the uttscadm component of the Windows Connector.Show less
1Sun
1Ray Server Software
Apr 23, 2026
Dec 11, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration G...Show more
Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration password, and obtain admin access to the Data Store and Administration GUI, via unspecified vectors.Show less
1Sun
1Ray Server Software
Apr 23, 2026
May 8, 2008
N/A· v4
N/A· v3
8.5 HIGH· v2
Unspecified vulnerability in Sun Ray Kiosk Mode 4.0 allows local and remote authenticated Sun Ray administrators to gain root privileges via unknown vectors related to utconfig.
1Sun
1Ray Server Software
Apr 23, 2026
Dec 20, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
1Sun
1Ray Server Software
Apr 23, 2026
Dec 20, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to create or delete arbitrary directories via unspecified vectors.
1Sun
1Ray Server Software
Apr 23, 2026
Jan 25, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.
1Sun
1Ray Server Software
Apr 16, 2026
Aug 9, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in the utxconfig utility in Sun Ray Server Software 3.x allows local users to create or overwrite arbitrary files via unknown attack vectors.
1Sun
1Ray Server Software
Apr 16, 2026
Jul 27, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay l...Show more
Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when the card is quickly removed, reinserted, and removed again, which could cause a user session to stay logged in and allow local users to gain unauthorized access.Show less
1Sun
1Ray Server Software
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.