Sun / Java System Web Server
32 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2010-0389 | The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) vi… | MEDIUM | 5.0 | Jan 25, 2010 |
| CVE-2010-0388 | Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of se… | HIGH | 7.5 | Jan 25, 2010 |
| CVE-2010-0387 | Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a deni… | HIGH | 7.5 | Jan 25, 2010 |
| CVE-2010-0361 | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a d… | HIGH | 10.0 | Jan 20, 2010 |
| CVE-2010-0360 | Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locat… | HIGH | 10.0 | Jan 20, 2010 |
| CVE-2010-0273 | Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory add… | HIGH | 7.5 | Jan 8, 2010 |
| CVE-2010-0272 | Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to… | HIGH | 7.5 | Jan 8, 2010 |
| CVE-2009-3878 | Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco… | HIGH | 9.3 | Nov 5, 2009 |
| CVE-2009-2713 | The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "polic… | MEDIUM | 4.3 | Aug 7, 2009 |
| CVE-2009-2712 | Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users… | LOW | 2.1 | Aug 7, 2009 |
| CVE-2009-2445 | Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allow… | MEDIUM | 5.0 | Jul 13, 2009 |
| CVE-2009-1934 | Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allows remote attackers to inject arbitrary… | MEDIUM | 4.3 | Jun 5, 2009 |
| CVE-2008-2518 | Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 be… | MEDIUM | 4.3 | Jun 3, 2008 |
| CVE-2008-2166 | Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to i… | MEDIUM | 4.3 | May 13, 2008 |
| CVE-2008-2120 | Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows… | MEDIUM | 5.0 | May 9, 2008 |
| CVE-2007-6572 | Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web s… | MEDIUM | 4.3 | Dec 28, 2007 |
| CVE-2007-6571 | Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script… | MEDIUM | 4.3 | Dec 28, 2007 |
| CVE-2007-6570 | Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 al… | MEDIUM | 4.3 | Dec 28, 2007 |
| CVE-2007-6569 | Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to in… | MEDIUM | 4.3 | Dec 28, 2007 |
| CVE-2007-4164 | CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (… | HIGH | 7.5 | Aug 7, 2007 |
| CVE-2007-3715 | Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures… | HIGH | 9.3 | Jul 11, 2007 |
| CVE-2007-1526 | Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CR… | MEDIUM | 6.0 | Mar 20, 2007 |
| CVE-2007-1488 | Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly inv… | HIGH | 7.5 | Mar 16, 2007 |
| CVE-2006-6276 | HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web… | MEDIUM | 6.8 | Dec 4, 2006 |
| CVE-2006-5654 | Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, w… | MEDIUM | 4.0 | Nov 3, 2006 |
Showing 1 to 25 of 32 CVEs