6.9
CVSSv2

CVE-2011-0902

Published: 07/02/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle sun_microsystems_sunscreen_firewall

Exploits

/* Sun Microsystems SunScreen Firewall Root Exploit discovered & exploited by Kingcope January 2011 The SunScreen Firewall can be administrated remotely via a java protocol service which is running on port 3858 on a SunOS machine This Java Service contains numerous buffer overruns (2 of which I am aware of) Furthermore it is possible to ex ...