← Back

Sun

sun

1,603 CVEs • 200 products

Products (200)

Click to collapse
Toggle
Sunos
sunos
Solaris
solaris
Jre
jre
Jdk
jdk
Sdk
sdk
Opensolaris
opensolaris
Openjdk
openjdk
Java
java
Java Se
java_se
Cobalt Raq 2
cobalt_raq_2
Cobalt Raq 3i
cobalt_raq_3i
Staroffice
staroffice
Cluster
cluster
J2se
j2se
Ehrd
ehrd
Cobalt Raq 4
cobalt_raq_4
Virtualbox
virtualbox
Chilisoft
chilisoft
Java Plug In
java_plug-in
Javamail
javamail
Grid Engine
grid_engine
Nfs
nfs
Cobalt Raq
cobalt_raq
Sun Fire
sun_fire
Jsse
jsse
J2ee
j2ee
I Runbook
i-runbook
Openwindows
openwindows
Fire X2100 M2
fire_x2100_m2
Fire X2200 M2
fire_x2200_m2
Workshop
workshop
Sun Ftp
sun_ftp
Sunvts
sunvts
Netdynamics
netdynamics
Linux
linux
Cobalt Raq Xtr
cobalt_raq_xtr
Patchpro
patchpro
Patch Manager
patch_manager
Seam
seam
Dtmail
dtmail
J2me
j2me
Netra 1280
netra_1280
Sunforum
sunforum

CVEs (1,603)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
4Java System Application Server
Java System Web Proxy ServerJava System Web Server+1 more
Apr 23, 2026
Dec 4, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filter...Show more
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified attack vectors.Show less
1Sun
2Solaris
Sunos
Apr 23, 2026
Dec 4, 2006
N/A· v4
N/A· v3
4.7 MEDIUM· v2
Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function and SIGKILL and /proc PCAGENT signals.
1Sun
2Jdk
Jre
Apr 23, 2026
Nov 21, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted app...Show more
Unspecified vulnerability in the Java Runtime Environment (JRE) Swing library in JDK and JRE 5.0 Update 7 and earlier allows attackers to obtain certain information via unknown attack vectors, related to an untrusted applet accessing data in other applets.Show less
1Sun
1Solaris
Apr 23, 2026
Nov 6, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.
1Sun
2Java System Web Server
One Application Server
Apr 23, 2026
Nov 3, 2006
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to ca...Show more
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details from the vendor, it is unclear whether this is related to vector 1 in CVE-2006-5201 or CVE-2006-3127.Show less
1Sun
1Java System Messenger Express
Apr 23, 2026
Nov 3, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE:...Show more
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.Show less
1Sun
1Iplanet Messaging Server Messenger Express
Apr 23, 2026
Nov 3, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated...Show more
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.Show less
1Sun
2Iplanet Messaging Server
Java System Messaging Server
Apr 23, 2026
Oct 24, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.
1Sun
1Solaris
Apr 23, 2026
Oct 18, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The tcp_fuse_rcv_drain function in the Sun Solaris 10 kernel before 20061017, when TCP Fusion is enabled, allows local users to cause a denial of service (system crash) via a TCP loopback connection with both endpoints o...Show more
The tcp_fuse_rcv_drain function in the Sun Solaris 10 kernel before 20061017, when TCP Fusion is enabled, allows local users to cause a denial of service (system crash) via a TCP loopback connection with both endpoints on the same system.Show less
2Netscape
Sun
2Portable Runtime Api
Solaris
Apr 23, 2026
Oct 12, 2006
N/A· v4
N/A· v3
3.6 LOW· v2
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users t...Show more
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.Show less
3Netbsd
SunX.org
4Netbsd
SolarisSunos+1 more
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's...Show more
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.Show less
2Netbsd
Sun
3Netbsd
SolarisSunos
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
1.2 LOW· v2
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak perm...Show more
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.Show less
1Sun
1Solaris
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
3.6 LOW· v2
Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).
1Sun
9Jdk
JreJsse+6 more
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5...Show more
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.Show less
1Sun
1Solaris
Apr 23, 2026
Sep 29, 2006
N/A· v4
N/A· v3
7.8 HIGH· v2
The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client.
1Sun
2Solaris
Sunos
Apr 23, 2026
Sep 29, 2006
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in Sun Solaris 8, 9 and 10 allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets, a different vulnerability than CVE-2006-5013.
1Sun
1Solaris
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
7.8 HIGH· v2
Sun Solaris 10 before patch 118855-16 (20060925), when run on x64 systems using IPv6, allows remote attackers to cause a denial of service (kernel panic) via crafted IPv6 packets.
1Sun
2Solaris
Sunos
Apr 23, 2026
Sep 27, 2006
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Unspecified vulnerability in Sun Solaris 8, 9, and 10 before 20060925 allows local users to cause a denial of service (disable syslog) and prevent security messages from being logged via unspecified vectors.
1Sun
1Secure Global Desktop
Apr 16, 2026
Sep 23, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, including hostnames, versions, and settings details, via unspecified vectors, possibly involving (1) ta...Show more
Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, including hostnames, versions, and settings details, via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available.Show less
1Sun
1Secure Global Desktop
Apr 16, 2026
Sep 23, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly inv...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi, (6) ttaabout.cgi, or (7) test-cgi. NOTE: This information is based upon a vague initial disclosure. Details will be updated as they become available.Show less