VendorsCrayunicosall versions
Vulnerabilities

Cray UNICOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-1999-0099
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
Published 1999-09-29 · Modified
10.0EPSS 0.033
CVE-1999-0692
The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
Published 2000-01-04 · Modified
10.0EPSS 0.024
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published 2003-03-21 · Modified
7.5EPSS 0.150
CVE-1999-0041
Buffer overflow in NLS (Natural Language Service).
Published 1999-09-29 · Modified
7.52 PoCEPSS 0.091
CVE-2006-0177
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.
Published 2006-01-11 · Modified
7.22 PoCEPSS 0.010
CVE-2001-0891
Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.
Published 2003-04-02 · Modified
7.2EPSS 0.003
CVE-2006-0178
Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.
Published 2006-01-11 · Modified
7.2EPSS 0.003
CVE-1999-1468
rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.
Published 2003-04-02 · Modified
6.2EPSS 0.003
CVE-1999-1300
Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.
Published 2001-09-12 · Modified
3.6EPSS 0.003