Show filters
295 Total Results
Displaying 171-180 of 295
Sort by:
Attacker Value
Unknown

CVE-2010-0708

Disclosure Date: February 25, 2010 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP search request.
0
Attacker Value
Unknown

CVE-2010-0386

Disclosure Date: January 25, 2010 (last updated October 04, 2023)
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
0
Attacker Value
Unknown

CVE-2010-0389

Disclosure Date: January 25, 2010 (last updated October 04, 2023)
The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token.
0
Attacker Value
Unknown

CVE-2010-0387

Disclosure Date: January 25, 2010 (last updated October 04, 2023)
Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.
0
Attacker Value
Unknown

CVE-2010-0388

Disclosure Date: January 25, 2010 (last updated October 04, 2023)
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.
0
Attacker Value
Unknown

CVE-2010-0361

Disclosure Date: January 20, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.
0
Attacker Value
Unknown

CVE-2010-0360

Disclosure Date: January 20, 2010 (last updated October 04, 2023)
Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and CVE-2010-0273.
0
Attacker Value
Unknown

CVE-2010-0313

Disclosure Date: January 14, 2010 (last updated October 04, 2023)
The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message.
0
Attacker Value
Unknown

CVE-2010-0311

Disclosure Date: January 14, 2010 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manager is used, allows remote attackers to obtain administrative access via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-0272

Disclosure Date: January 08, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
0