Show filters
295 Total Results
Displaying 241-250 of 295
Sort by:
Attacker Value
Unknown
CVE-2007-5153
Disclosure Date: October 01, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-4511
Disclosure Date: August 23, 2007 (last updated October 04, 2023)
The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.
0
Attacker Value
Unknown
CVE-2007-4289
Disclosure Date: August 09, 2007 (last updated October 04, 2023)
Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3715.
0
Attacker Value
Unknown
CVE-2007-4164
Disclosure Date: August 07, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks.
0
Attacker Value
Unknown
CVE-2007-4025
Disclosure Date: July 26, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-3715
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
0
Attacker Value
Unknown
CVE-2007-3225
Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-3224
Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-2904
Disclosure Date: May 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.
0
Attacker Value
Unknown
CVE-2007-2881
Disclosure Date: May 29, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.
0