← Back

Sun

sun

1,603 CVEs • 200 products

Products (200)

Click to collapse
Toggle
Sunos
sunos
Solaris
solaris
Jre
jre
Jdk
jdk
Sdk
sdk
Opensolaris
opensolaris
Openjdk
openjdk
Java
java
Java Se
java_se
Cobalt Raq 2
cobalt_raq_2
Cobalt Raq 3i
cobalt_raq_3i
Staroffice
staroffice
Cluster
cluster
J2se
j2se
Ehrd
ehrd
Cobalt Raq 4
cobalt_raq_4
Virtualbox
virtualbox
Chilisoft
chilisoft
Java Plug In
java_plug-in
Javamail
javamail
Grid Engine
grid_engine
Nfs
nfs
Cobalt Raq
cobalt_raq
Sun Fire
sun_fire
Jsse
jsse
J2ee
j2ee
I Runbook
i-runbook
Openwindows
openwindows
Fire X2100 M2
fire_x2100_m2
Fire X2200 M2
fire_x2200_m2
Workshop
workshop
Sun Ftp
sun_ftp
Sunvts
sunvts
Netdynamics
netdynamics
Linux
linux
Cobalt Raq Xtr
cobalt_raq_xtr
Patchpro
patchpro
Patch Manager
patch_manager
Seam
seam
Dtmail
dtmail
J2me
j2me
Netra 1280
netra_1280
Sunforum
sunforum

CVEs (1,603)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sun
2Java Runtime Environment
Java Se Development Kit
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via c...Show more
Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.Show less
1Sun
3Jdk
JreSdk
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access fil...Show more
Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.Show less
1Sun
2Jdk
Jre
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that trig...Show more
Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.Show less
1Sun
2Jdk
Jre
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code v...Show more
Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.Show less
1Sun
2Jdk
Jre
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code...Show more
Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.Show less
1Sun
3Jdk
JreSdk
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19...Show more
Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.Show less
1Sun
3Jdk
JreSdk
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not clos...Show more
LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspe...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vec...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and othe...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 1...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 1966...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to c...Show more
The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumer...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid user...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.Show less
1Sun
1Java System Identity Manager
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl t...Show more
Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.Show less
4Gimp
LittlecmsMozilla+1 more
4Firefox
GimpLittle Cms+1 more
Apr 23, 2026
Mar 23, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbit...Show more
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.Show less
4Gimp
LittlecmsMozilla+1 more
4Firefox
GimpLittle Cms+1 more
Apr 23, 2026
Mar 23, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that tri...Show more
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.Show less