← Back

Sun

sun

1,603 CVEs • 200 products

Products (200)

Click to collapse
Toggle
Sunos
sunos
Solaris
solaris
Jre
jre
Jdk
jdk
Sdk
sdk
Opensolaris
opensolaris
Openjdk
openjdk
Java
java
Java Se
java_se
Cobalt Raq 2
cobalt_raq_2
Cobalt Raq 3i
cobalt_raq_3i
Staroffice
staroffice
Cluster
cluster
J2se
j2se
Ehrd
ehrd
Cobalt Raq 4
cobalt_raq_4
Virtualbox
virtualbox
Chilisoft
chilisoft
Java Plug In
java_plug-in
Javamail
javamail
Grid Engine
grid_engine
Nfs
nfs
Cobalt Raq
cobalt_raq
Sun Fire
sun_fire
Jsse
jsse
J2ee
j2ee
I Runbook
i-runbook
Openwindows
openwindows
Fire X2100 M2
fire_x2100_m2
Fire X2200 M2
fire_x2200_m2
Workshop
workshop
Sun Ftp
sun_ftp
Sunvts
sunvts
Netdynamics
netdynamics
Linux
linux
Cobalt Raq Xtr
cobalt_raq_xtr
Patchpro
patchpro
Patch Manager
patch_manager
Seam
seam
Dtmail
dtmail
J2me
j2me
Netra 1280
netra_1280
Sunforum
sunforum

CVEs (1,603)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
3Jdk
JreSdk
Apr 29, 2026
Apr 1, 2010
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and avail...Show more
Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.Show less
1Sun
1Solaris
Apr 29, 2026
Mar 29, 2010
N/A· v4
N/A· v3
3.3 LOW· v2
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.
1Sun
1Java System Directory Server
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 thr...Show more
Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP search request.Show less
1Sun
1One Web Server
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors.
1Sun
1One Web Server
Apr 29, 2026
Feb 25, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors.
1Sun
1Cluster
Apr 29, 2026
Feb 8, 2010
N/A· v4
N/A· v3
1.9 LOW· v2
Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file...Show more
Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.Show less
1Sun
1Opensolaris
Apr 29, 2026
Feb 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.
1Sun
1Opensolaris
Apr 29, 2026
Feb 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.
1Sun
1One Web Server
Apr 29, 2026
Feb 5, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows...Show more
Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.Show less
1Sun
1One Web Server
Apr 29, 2026
Feb 5, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompany...Show more
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.Show less
1Sun
1One Web Server
Apr 29, 2026
Feb 5, 2010
N/A· v4
N/A· v3
2.6 LOW· v2
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scrip...Show more
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a crafted DNS response, related to an "Inverse Lookup Log Corruption (ILLC)" issue, a different vulnerability than CVE-2002-1315 and CVE-2002-1316.Show less
1Sun
2Opensolaris
Solaris
Apr 29, 2026
Feb 3, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0...Show more
The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.Show less
1Sun
1Storedge 6130 Arrays
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.
1Sun
2Iplanet Messaging Server
One Messaging Server
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" is...Show more
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.Show less
1Sun
2Iplanet Messaging Server
One Messaging Server
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web scrip...Show more
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.Show less
1Sun
1Change Manager
Apr 29, 2026
Jan 28, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in pamverifier in Change Manager (CM) 1.0 for Sun Management Center (SunMC) 3.0 on Solaris 8 and 9 on the sparc platform allows remote attackers to execute arbitrary code via unspecified vectors.
1Sun
1Java System Web Server
Apr 29, 2026
Jan 25, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token.
1Sun
1Java System Web Server
Apr 29, 2026
Jan 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impa...Show more
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.Show less
1Sun
1Java System Web Server
Apr 29, 2026
Jan 25, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified ot...Show more
Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.Show less
1Sun
1Java System Application Server
May 28, 2026
Jan 25, 2010
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tr...Show more
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.Show less