VendorsSGIirixall versions
Vulnerabilities

SGI Irix

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

187CVEs
CVE-1999-0270
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.
Published 2000-01-18 · Modified
5.0EPSS 0.321
CVE-2003-0688
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
Published 2003-09-03 · Modified
5.0EPSS 0.036
CVE-2000-1193
Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.
Published 2002-06-25 · Modified
5.01 PoCEPSS 0.033
CVE-2002-1265
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
Published 2004-09-01 · Modified
5.0EPSS 0.025
CVE-2003-0472
The IPv6 capability in IRIX 6.5.19 allows remote attackers to cause a denial of service (hang) in inetd via port scanning.
Published 2003-06-28 · Modified
5.0EPSS 0.025
CVE-2004-1889
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.
Published 2005-05-10 · Modified
5.0EPSS 0.024
CVE-1999-1131
Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.
Published 2002-03-09 · Modified
5.0EPSS 0.021
CVE-1999-0083
getcwd() file descriptor leak in FTP.
Published 1999-09-29 · Modified
5.0EPSS 0.018
CVE-2004-0483
Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.
Published 2004-05-20 · Modified
5.0EPSS 0.018
CVE-1999-0019
Delete or create a file via rpc.statd, due to invalid information.
Published 1999-09-29 · Modified
5.0EPSS 0.017
CVE-2002-0041
Unknown vulnerability in Mail for SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, when running with the -R option, allows local and remote attackers to cause a core dump.
Published 2002-04-12 · Modified
5.0EPSS 0.016
CVE-2002-0038
Vulnerability in the cache-limiting function of the unified name service daemon (nsd) in IRIX 6.5.4 through 6.5.11 allows remote attackers to cause a denial of service by forcing the cache to fill the disk.
Published 2002-06-25 · Modified
5.0EPSS 0.016
CVE-2001-0796
SGI IRIX 6.5 through 6.5.12f and possibly earlier versions, and FreeBSD 3.0, allows remote attackers to cause a denial of service via a malformed IGMP multicast packet with a small response delay.
Published 2002-03-09 · Modified
5.0EPSS 0.016
CVE-2003-0797
Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.
Published 2004-03-10 · Modified
5.0EPSS 0.016
CVE-2004-2002
Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.
Published 2005-05-10 · Modified
5.0EPSS 0.016
CVE-2004-1890
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.
Published 2005-05-10 · Modified
5.0EPSS 0.016
CVE-1999-0195
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
Published 2000-02-04 · Modified
5.0EPSS 0.015
CVE-2000-0893
The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.
Published 2001-02-02 · Modified
5.0EPSS 0.015
CVE-2003-0572
Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).
Published 2003-08-18 · Modified
5.0EPSS 0.014
CVE-2003-0573
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.
Published 2003-08-18 · Modified
5.0EPSS 0.013
CVE-1999-1067
SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.
Published 2001-09-12 · Modified
5.0EPSS 0.013
CVE-2002-0632
Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server.
Published 2002-08-14 · Modified
5.0EPSS 0.013
CVE-2003-0176
The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.
Published 2003-08-18 · Modified
5.0EPSS 0.013
CVE-2002-0039
rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths.
Published 2002-03-30 · Modified
5.0EPSS 0.013
CVE-2003-0576
Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, a different vulnerability than CVE-2003-0619.
Published 2003-08-15 · Modified
5.0EPSS 0.013
CVE-2004-1891
The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.
Published 2005-05-10 · Modified
5.0EPSS 0.009
CVE-2002-2185
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
Published 2005-11-16 · Modified
4.9EPSS 0.025
CVE-1999-0125
Buffer overflow in SGI IRIX mailx program.
Published 1999-09-29 · Modified
4.62 PoCEPSS 0.011
CVE-1999-0026
root privileges via buffer overflow in pset command on SGI IRIX systems.
Published 1999-09-29 · Modified
4.61 PoCEPSS 0.009
CVE-1999-1120
netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.
Published 2002-03-09 · Modified
4.61 PoCEPSS 0.008
CVE-1999-1243
SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.
Published 2002-03-09 · Modified
4.61 PoCEPSS 0.006
CVE-2002-1787
Buffer overflow in uux in eoe.sw.uucp package of SGI IRIX 6.5 through 6.5.17 allows local users to execute arbitrary code via unknown attack vectors.
Published 2005-06-28 · Modified
4.6EPSS 0.005
CVE-2002-1323
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
Published 2004-09-01 · Modified
4.6EPSS 0.005
CVE-1999-0234
Bash treats any character with a value of 255 as a command separator.
Published 1999-09-29 · Modified
4.6EPSS 0.004
CVE-1999-1501
(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.
Published 2001-09-12 · Modified
4.6EPSS 0.004
CVE-1999-1401
Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).
Published 2001-09-12 · Modified
4.6EPSS 0.004
CVE-2002-1517
fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file.
Published 2004-09-01 · Modified
4.6EPSS 0.003
CVE-2003-0177
SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.
Published 2003-08-18 · Modified
4.6EPSS 0.003
CVE-2002-1516
rpcbind in SGI IRIX, when using the -w command line switch, allows local users to overwrite arbitrary files via a symlink attack.
Published 2004-09-01 · Modified
4.6EPSS 0.003
CVE-2004-2001
ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.
Published 2005-05-10 · Modified
4.6EPSS 0.003
← Prev4 / 5Next →