CVE-2006-3225
https://notcve.org/view.php?id=CVE-2006-3225
Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Sun ONE Application Server v7 anterior a actualización v9, Java System Application Server v7 2004Q2 anterior a actualización v5, y Java System Application Server Enterprise Edition v8.1 2005 Q1 permite a atacantes remotos inyecatr código HTML o web a través de vectores desconocidos. • http://secunia.com/advisories/20835 http://securitytracker.com/id?1016378 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102479-1 http://www.securityfocus.com/bid/18635 http://www.vupen.com/english/advisories/2006/2508 https://exchange.xforce.ibmcloud.com/vulnerabilities/27392 •
CVE-2006-3127
https://notcve.org/view.php?id=CVE-2006-3127
Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2, allows remote attackers to cause a denial of service (memory consumption) by performing a large number of RSA cryptographic operations. Fallo de memoria en la Red de Servicios de Seguridad (NSS) 3.11, tal como se utiliza en Sun Java Enterprise System 2003Q4 2005Q1 y por medio de Java System Directory Server 5.2, permite a atacantes remotos causar una denegación de servicio (consumo de memoria) mediante la realización de un gran número de operaciones de cifrado RSA . • http://secunia.com/advisories/25048 http://securitytracker.com/id?1016294 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102461-1 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102896-1 http://www.redhat.com/archives/fedora-package-announce/2006-June/msg00155.html http://www.securityfocus.com/bid/18604 http://www.securityfocus.com/bid/20846 http://www.vupen.com/english/advisories/2007/1573 • CWE-399: Resource Management Errors •
CVE-2006-2513
https://notcve.org/view.php?id=CVE-2006-2513
Unspecified vulnerability in the installation process in Sun Java System Directory Server 5.2 causes wrong user data to be written to a file created by the installation, which allows remote attackers or local users to gain privileges. • http://secunia.com/advisories/20144 http://securitytracker.com/id?1016112 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102345-1 http://www.securityfocus.com/bid/18018 http://www.vupen.com/english/advisories/2006/1832 https://exchange.xforce.ibmcloud.com/vulnerabilities/26477 •
CVE-2006-2501
https://notcve.org/view.php?id=CVE-2006-2501
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving error messages. • http://jvn.jp/jp/JVN%2303D5EAA8/index.html http://secunia.com/advisories/20147 http://securitytracker.com/id?1016125 http://securitytracker.com/id?1016126 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102164-1 http://www.kb.cert.org/vuls/id/114956 http://www.securityfocus.com/bid/18035 http://www.vupen.com/english/advisories/2006/1866 https://exchange.xforce.ibmcloud.com/vulnerabilities/26550 •
CVE-2006-1830
https://notcve.org/view.php?id=CVE-2006-1830
Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors. • http://secunia.com/advisories/19632 http://securitytracker.com/id?1015930 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102292-1 http://www.securityfocus.com/bid/17517 http://www.vupen.com/english/advisories/2006/1357 https://exchange.xforce.ibmcloud.com/vulnerabilities/25822 •