peter bassill · operator
$ cve CVE-2011-0902 JSON

CVE-2011-0902 EXPLOIT

6.9
MEDIUM · CVSS 2.0 · EPSS 1.5% (pctl 74)

Patch early

A public exploit exists.

Description

Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 allow local users to execute arbitrary code via a modified (1) PATH or (2) LD_LIBRARY_PATH environment variable.

Scoring

CVSS6.9 (MEDIUM, v2.0)
VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS1.52% — more likely to be exploited than 74% of all CVEs
On CISA KEVno
Public exploityes
Published2011-02-07
Last modified2026-06-16

Affected (2)

VendorProduct
oraclesun microsystems sunscreen firewall
sunsunos

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD