Page 10 of 214 results (0.011 seconds)

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

Cross-site scripting (XSS) vulnerability in /prm/reports in the Performance Reporting Module (PRM) for Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: this can be leveraged for access to the SunMC Web Console. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados(XSS) en /prm/reports en Performance Reporting Module (PRM) para Sun Management Center (SunMC) v3.6.1 y v4.0, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro "msg". NOTA: esto puede ser aprovechados para el acceso a la Consola Web SunMC. • http://secunia.com/advisories/34146 http://securitytracker.com/id?1021809 http://sunsolve.sun.com/search/document.do?assetkey=1-21-125191-04-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-247046-1 http://www.securityfocus.com/bid/33999 http://www.vupen.com/english/advisories/2009/0605 https://exchange.xforce.ibmcloud.com/vulnerabilities/49076 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.9EPSS: 0%CPEs: 168EXPL: 0

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets. La implementación IP en Sun Solaris v8 a la v10 y OpenSolaris anterior a snv_82, emplea una arena inadecuada cuando al asignar números secundarios para sockets, lo que permite a usuarios locales provocar una denegación de servicio (fallo en la aplicación 32-bit o parada de login) mediante la apertura de un gran número de sockets. • http://mail.opensolaris.org/pipermail/onnv-notify/2008-January/013262.html http://secunia.com/advisories/33751 http://securitytracker.com/id?1021653 http://sunsolve.sun.com/search/document.do?assetkey=1-21-116965-34-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-248026-1 http://support.avaya.com/elmodocs2/security/ASA-2009-042.htm http://www.securityfocus.com/bid/33550 http://www.vupen.com/english/advisories/2009/0364 https://oval.cisecurity.org/repository/search/def • CWE-189: Numeric Errors •

CVSS: 4.9EPSS: 0%CPEs: 190EXPL: 0

The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection. La implementacion del procesado del paquete IP-en-IP en la pila de IPsec e IP en Sun Solaris v9 y v10, y OpenSolaris desde snv_01 hasta snv_85, permite a usuarios locales producir una denegacion de servicio (panic) a traves de un paquete autoencapsulado que carece de proteccion IPsec. • http://secunia.com/advisories/33727 http://sunsolve.sun.com/search/document.do?assetkey=1-21-114344-38-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-240086-1 http://support.avaya.com/elmodocs2/security/ASA-2009-043.htm http://www.securityfocus.com/bid/33504 http://www.vupen.com/english/advisories/2009/0365 https://exchange.xforce.ibmcloud.com/vulnerabilities/48328 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6088 • CWE-310: Cryptographic Issues •

CVSS: 6.9EPSS: 0%CPEs: 210EXPL: 0

Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems." Vulnerabilidad sin especificar en el módulo autofs en el kernel en Sun Solaris 8 a la 10, y OpenSolaris anterior a snv_108, permite a usuarios locales provocar una denegación de servicio (parada del montaje autofs) o posiblemente la obtención de privilegios a través de vectores relacionados con "problemas de procesado xdr (xdr processing problems)." • http://secunia.com/advisories/33665 http://sunsolve.sun.com/search/document.do?assetkey=1-21-128624-09-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-249966-1 http://support.avaya.com/elmodocs2/security/ASA-2009-041.htm http://www.securityfocus.com/bid/33459 http://www.securitytracker.com/id?1021644 http://www.vupen.com/english/advisories/2009/0256 http://www.vupen.com/english/advisories/2009/0363 https://exchange.xforce.ibmcloud.com/vulnerabilities/48234 https:/ •

CVSS: 4.9EPSS: 0%CPEs: 210EXPL: 0

Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl. Una condición de carrera en el pseudo-terminal (alias PTY) en el módulo controlador de Sun Solaris 8 a 10, y OpenSolaris en versiones anteriores a la snv_103, permite a usuarios locales provocar una denegación de servicio (con un panic del kernel) a través de vectores no especificados relacionados con la falta de "código correctamente secuenciado" en PTC y PTSL. • http://secunia.com/advisories/33708 http://sunsolve.sun.com/search/document.do?assetkey=1-21-113685-07-1 http://sunsolve.sun.com/search/document.do?assetkey=1-66-249586-1 http://support.avaya.com/elmodocs2/security/ASA-2009-034.htm http://www.securityfocus.com/bid/33406 http://www.securitytracker.com/id?1021640 https://exchange.xforce.ibmcloud.com/vulnerabilities/48179 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6061 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •