← Back to Vendors

sun

Security Vendor Profile

158
Products
25,892
Total CVEs
6,183
Critical
6,699
High
7,806
Medium
5,204
Low

Average CVSS Score

5.3

Top Products by CVE Count

jre
125 Critical 309 CVEs
jdk
119 Critical 292 CVEs
jre
91 Critical 237 CVEs
jdk
87 Critical 214 CVEs
sunos
22 Critical 195 CVEs
sunos
24 Critical 145 CVEs
jre
51 Critical 134 CVEs
jre
51 Critical 133 CVEs
jre
51 Critical 133 CVEs
jre
51 Critical 133 CVEs

Recent CVEs

Product: opensolaris

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST...

Published: Apr 6, 2016

9.3

CVSS

Product: opensolaris

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain...

Published: Apr 6, 2016

5.5

CVSS

Product: opensolaris

Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to caus...

Published: Apr 6, 2016

7.8

CVSS

Product: opensolaris

Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug...

Published: Mar 28, 2016

3.5

CVSS

Product: opensolaris

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug...

Published: Mar 26, 2016

7.8

CVSS

Product: opensolaris

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list paramet...

Published: Mar 26, 2016

7.8

CVSS

Product: opensolaris

Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821....

Published: Mar 26, 2016

7.8

CVSS

Product: opensolaris

The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417....

Published: Mar 26, 2016

7.1

CVSS

Product: opensolaris

Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload)...

Published: Mar 3, 2016

7.8

CVSS

Product: opensolaris

Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to ...

Published: Mar 3, 2016

10.0

CVSS

Product: opensolaris

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CS...

Published: Feb 15, 2016

4.3

CVSS

Product: opensolaris

Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Co...

Published: Feb 9, 2016

5.0

CVSS

Product: opensolaris

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11....

Published: Feb 7, 2016

9.0

CVSS

Product: opensolaris

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033....

Published: Feb 6, 2016

4.3

CVSS

Product: opensolaris

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466....

Published: Feb 6, 2016

4.3

CVSS

Product: opensolaris

SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID ...

Published: Jan 27, 2016

10.0

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality via vectors related to RPC Utility....

Published: Jan 21, 2015

1.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to RPC Utility....

Published: Jan 21, 2015

3.3

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Resource Control....

Published: Jan 21, 2015

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6570 and CVE-2014-6600....

Published: Jan 21, 2015

2.1

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect confidentiality via unknown vectors related to Network....

Published: Jan 21, 2015

5.0

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6570 and CVE-2015-0397....

Published: Jan 21, 2015

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE-2004-0230....

Published: Jan 21, 2015

5.0

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6600 and CVE-2015-0397....

Published: Jan 21, 2015

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel....

Published: Jan 21, 2015

7.2

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via vectors related to CDE - Power Management Utility....

Published: Jan 21, 2015

7.2

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS)....

Published: Jan 21, 2015

6.6

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility....

Published: Jan 21, 2015

7.2

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability via unknown vectors related to Kernel....

Published: Jan 21, 2015

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidentiality via vectors related to KSSL....

Published: Jan 21, 2015

4.3

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hermon HCA PCIe driver....

Published: Oct 15, 2014

6.8

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to iSCSI Data Mover (IDM)....

Published: Oct 15, 2014

7.8

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via vectors related to SSH....

Published: Oct 15, 2014

2.1

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Kernel....

Published: Oct 15, 2014

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB server user component....

Published: Oct 15, 2014

5.0

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Zone Framework....

Published: Oct 15, 2014

7.2

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Archive Utility....

Published: Oct 15, 2014

6.8

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than ...

Published: Oct 15, 2014

4.4

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality via unknown vectors related to Automated Install Engine, a different vulnerability than CVE-2014-42...

Published: Oct 15, 2014

4.3

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel/X86....

Published: Oct 15, 2014

7.2

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than ...

Published: Oct 15, 2014

4.6

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality via unknown vectors related to Automated Install Engine, a different vulnerability than CVE-2014-42...

Published: Oct 15, 2014

5.0

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Common Internet File System (CIFS)....

Published: Oct 15, 2014

7.5

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via vectors related to SMB server kernel module....

Published: Oct 15, 2014

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Common Agent Container (Cacao)....

Published: Jul 17, 2014

4.0

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Patch installation scripts....

Published: Jul 17, 2014

6.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows local users to affect availability via unknown vectors related to sockfs....

Published: Jul 17, 2014

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to CPU performance counters (CPC) drivers, a different vulnerability than CVE-2013...

Published: Jul 17, 2014

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2013-5876....

Published: Apr 16, 2014

4.9

CVSS

Product: sunos

Unspecified vulnerability in Oracle Solaris 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Print Filter Utility....

Published: Apr 16, 2014

4.6

CVSS