Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sun

First CVE: Jul 26, 1989Active for: 37 yearsTotal CVEs: 1,711
55.7
VTI Score
TOP TARGET

Sun's vulnerability footprint spans a substantial historical portfolio centered on operating systems, Java runtime environments, and development kits that have been deeply embedded across enterprise infrastructure, servers, and client deployments. The vendor's disclosures frequently acquire public exploit code, reflecting both the widespread reach of products such as Solaris, SunOS, and the Java Runtime Environment and the long operational lifespans of many affected systems. The recurring weakness classes center on memory-safety issues including buffer-boundary violations, input-validation and neutralization flaws in web-facing contexts, and a significant share of NVD placeholder classifications that reflect the age and documentation gaps in some of these disclosures. Defenders should prioritize inventory of legacy Sun systems still in operation and treat Java runtime updates as broadly applicable across the enterprise; live severity, exploitation activity, and current CVE counts are shown alongside this summary.

FAUCET AI Generated
1,711
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Sun over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 1989
36 years ago
Most Recent CVE
Dec 1, 2021
1,696 days ago

Products(200 total)

Top CVEs

Signals from CVEs in this vendor scope (1711 CVEs).

1,711 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2465CRITICAL
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and Ope
Jun 18, 20139.898YESYES
CVE-2012-0507CRITICAL
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows re
Jun 7, 20129.898YESYES
CVE-2007-0882HIGH
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the
Feb 12, 200710.091NOYES
CVE-2011-2140HIGH
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.
Aug 10, 201110.090NOYES
CVE-2013-1493HIGH
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attacke
Mar 5, 201310.089NOYES
CVE-2011-2110HIGH
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a
Jun 16, 201110.089NOYES
CVE-2010-3563HIGH
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availabi
Oct 19, 201010.089NOYES
CVE-2010-4452HIGH
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote untrusted Java
Feb 17, 201110.088NOYES
CVE-2010-3552HIGH
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and av
Oct 19, 201010.088NOYES
CVE-2008-5353HIGH
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforc
Dec 5, 200810.088NOYES
View all 1,711 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,711 CVEs
11%
43%
46%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (0.4%)
Network32 (1.9%)
Unknown1,672 (97.7%)
Physical0 (0.0%)
Adjacent Network1 (0.1%)
Attack Complexity
Low36 (2.1%)
High3 (0.2%)
Unknown1,672 (97.7%)
User Interaction
None32 (1.9%)
Unknown1,672 (97.7%)
Required7 (0.4%)
Privileges Required
Low7 (0.4%)
High0 (0.0%)
None32 (1.9%)
Unknown1,672 (97.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (1711 CVEs).

CISA KEV
2 CVEs
0.1% of CVEs· 99th percentile
Metasploit
37 CVEs
2.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
239 CVEs
14.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sun.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sun — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sun's Products

View all 10 CNAs →

Top CWEs