VendorsSGIirixall versions
Vulnerabilities

SGI Irix

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Published 2003-03-21 · Modified
7.5EPSS 0.150
CVE-1999-0148
The handler CGI program in IRIX allows arbitrary command execution.
Published 1999-09-29 · Modified
7.51 PoCEPSS 0.105
CVE-2002-0652
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().
Published 2002-07-01 · Modified
7.51 PoCEPSS 0.091
CVE-2000-0207
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.
Published 2000-04-10 · Modified
7.51 PoCEPSS 0.077
CVE-2002-0677
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
Published 2002-07-12 · Modified
7.5EPSS 0.066
CVE-2001-1456
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
Published 2005-04-21 · Modified
7.5EPSS 0.057
CVE-2001-0331
Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.
Published 2001-09-18 · Modified
7.5EPSS 0.033
CVE-2002-0017
Buffer overflow in SNMP daemon (snmpd) on SGI IRIX 6.5 through 6.5.15m allows remote attackers to execute arbitrary code via an SNMP request.
Published 2003-04-02 · Modified
7.5EPSS 0.033
CVE-1999-0149
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.
Published 1999-09-29 · Modified
7.51 PoCEPSS 0.027
CVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
Published 2004-09-01 · Modified
7.5EPSS 0.027
CVE-2003-0796
Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.
Published 2004-03-10 · Modified
7.5EPSS 0.015
CVE-2002-1419
The upgrade of IRIX on Origin 3000 to 6.5.13 through 6.5.16 changes the MAC address of the system, which could modify intended access restrictions that are based on a MAC address.
Published 2004-09-01 · Modified
7.5EPSS 0.015
CVE-2003-0683
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.
Published 2003-10-30 · Modified
7.5EPSS 0.014
CVE-2005-0139
Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.
Published 2005-09-21 · Modified
7.5EPSS 0.013
CVE-2005-0138
rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.
Published 2005-09-21 · Modified
7.5EPSS 0.013
CVE-2003-0680
Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.
Published 2003-09-18 · Modified
7.5EPSS 0.012
CVE-1999-0059
IRIX fam service allows an attacker to obtain a list of all files on the server.
Published 1999-09-29 · Modified
7.3EPSS 0.016
CVE-1999-0025
root privileges via buffer overflow in df command on SGI IRIX systems.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.123
CVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
Published 2003-04-02 · Modified
7.2EPSS 0.094
CVE-1999-1384
Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.016
CVE-1999-0051
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
Published 1999-09-29 · Modified
7.23 PoCEPSS 0.013
CVE-1999-1219
Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.013
CVE-1999-0040
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Published 1999-09-29 · Modified
7.25 PoCEPSS 0.012
CVE-2000-0795
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
Published 2002-03-09 · Modified
7.22 PoCEPSS 0.012
CVE-1999-0027
root privileges via buffer overflow in eject command on SGI IRIX systems.
Published 1999-09-29 · Modified
7.23 PoCEPSS 0.012
CVE-2001-0485
Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.
Published 2004-09-01 · Modified
7.22 PoCEPSS 0.012
CVE-2000-0796
Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.011
CVE-1999-1114
Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.
Published 2002-03-09 · Modified
7.21 PoCEPSS 0.011
CVE-1999-0030
root privileges via buffer overflow in xlock command on SGI IRIX systems.
Published 2000-02-04 · Modified
7.22 PoCEPSS 0.011
CVE-2000-0797
Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.
Published 2004-09-01 · Modified
7.21 PoCEPSS 0.011
CVE-1999-0032
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
Published 1999-09-29 · Modified
7.22 PoCEPSS 0.010
CVE-1999-1461
inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.010
CVE-1999-1399
spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.009
CVE-2005-2925
runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.
Published 2005-10-11 · Modified
7.21 PoCEPSS 0.008
CVE-2000-0794
Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.
Published 2000-09-21 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0044
fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0314
ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0108
The printers program in IRIX has a buffer overflow that gives root access to local users.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.007
CVE-1999-1286
addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.007
CVE-1999-0959
IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.
Published 2000-07-12 · Modified
7.21 PoCEPSS 0.007
← Prev2 / 5Next →