← Back

Sun

sun

1,603 CVEs • 200 products

Products (200)

Click to collapse
Toggle
Sunos
sunos
Solaris
solaris
Jre
jre
Jdk
jdk
Sdk
sdk
Opensolaris
opensolaris
Openjdk
openjdk
Java
java
Java Se
java_se
Cobalt Raq 2
cobalt_raq_2
Cobalt Raq 3i
cobalt_raq_3i
Staroffice
staroffice
Cluster
cluster
J2se
j2se
Ehrd
ehrd
Cobalt Raq 4
cobalt_raq_4
Virtualbox
virtualbox
Chilisoft
chilisoft
Java Plug In
java_plug-in
Javamail
javamail
Grid Engine
grid_engine
Nfs
nfs
Cobalt Raq
cobalt_raq
Sun Fire
sun_fire
Jsse
jsse
J2ee
j2ee
I Runbook
i-runbook
Openwindows
openwindows
Fire X2100 M2
fire_x2100_m2
Fire X2200 M2
fire_x2200_m2
Workshop
workshop
Sun Ftp
sun_ftp
Sunvts
sunvts
Netdynamics
netdynamics
Linux
linux
Cobalt Raq Xtr
cobalt_raq_xtr
Patchpro
patchpro
Patch Manager
patch_manager
Seam
seam
Dtmail
dtmail
J2me
j2me
Netra 1280
netra_1280
Sunforum
sunforum

CVEs (1,603)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
1Sunos
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.
1Sun
2Solaris
Sunos
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
1Sun
1Sun Ftp
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.
1Sun
1Sunos
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
1Sun
2Solaris
Sunos
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
1Sun
1Chilisoft
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.
1Sun
2Solaris
Sunos
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
1Sun
2Solaris
Sunos
Apr 16, 2026
Mar 26, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).
1Sun
2Solaris
Sunos
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.
1Sun
2Solaris
Sunos
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.
1Sun
1Sunos
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.
1Sun
1Cluster
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.
1Sun
1Cluster
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.
1Sun
1Sunos
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
6.2 MEDIUM· v2
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
1Sun
1Staroffice
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
3.6 LOW· v2
StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.
1Sun
1Jdk
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthor...Show more
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.Show less
1Sun
1Hotjava Browser
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.
2Lbl
Sun
2Lbl Traceroute
Sunos
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
2Netscape
Sun
2Directory Server
Iplanet Certificate Management System
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on t...Show more
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.Show less
2Netscape
Sun
2Directory Server
Iplanet Certificate Management System
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrato...Show more
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.Show less