Sgi Irix vulnerabilities
161 known vulnerabilities affecting sgi/irix.
Total CVEs
161
CISA KEV
0
Public exploits
59
Exploited in wild
0
Severity breakdown
CRITICAL29HIGH69MEDIUM39LOW24
Vulnerabilities
Page 5 of 9
CVE-2001-0331HIGHCVSS 7.5≤ 6.5.8v6.5.52001-06-27
CVE-2001-0331 [HIGH] CVE-2001-0331: Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows
Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.
nvd
CVE-2001-0248CRITICALCVSS 9.8v6.5v6.5.1+1 more2001-06-18
CVE-2001-0248 [CRITICAL] CWE-131 CVE-2001-0248: Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by cr
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.
nvd
CVE-2001-0247CRITICALCVSS 10.0PoCv6.1v6.5.1+11 more2001-06-18
CVE-2001-0247 [CRITICAL] CVE-2001-0247: Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.
nvd
CVE-2001-0249CRITICALCVSS 9.8≥ 6.5, ≤ 6.5.202001-06-18
CVE-2001-0249 [CRITICAL] CWE-131 CVE-2001-0249: Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by cr
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.
nvd
CVE-2000-0844CRITICALCVSS 10.0PoCv6.2v6.3+11 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-2000-0798CRITICALCVSS 10.0PoCv6.2v6.3+1 more2000-10-20
CVE-2000-0798 [CRITICAL] CVE-2000-0798: The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs
The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.
nvd
CVE-2000-0733CRITICALCVSS 10.0PoCv5.2v5.3+16 more2000-10-20
CVE-2000-0733 [CRITICAL] CVE-2000-0733: Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings,
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.
nvd
CVE-2000-0794HIGHCVSS 7.2PoCv6.22000-10-20
CVE-2000-0794 [HIGH] CVE-2000-0794: Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME
Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.
nvd
CVE-2000-0797HIGHCVSS 7.2PoCv6.2v6.32000-10-20
CVE-2000-0797 [HIGH] CVE-2000-0797: Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D
Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.
nvd
CVE-2000-0795HIGHCVSS 7.2PoCv6.2v6.32000-10-20
CVE-2000-0795 [HIGH] CVE-2000-0795: Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
nvd
CVE-2000-0796HIGHCVSS 7.2PoCv6.2v6.32000-10-20
CVE-2000-0796 [HIGH] CVE-2000-0796: Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long
Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.
nvd
CVE-2000-0799LOWCVSS 3.7PoCv6.5v6.5.1+8 more2000-10-20
CVE-2000-0799 [LOW] CVE-2000-0799: inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a
inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file.
nvd
CVE-2000-0579LOWCVSS 3.7v6.3v6.52000-06-21
CVE-2000-0579 [LOW] CVE-2000-0579: IRIX crontab creates temporary files with predictable file names and with the umask of the user, whi
IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited.
nvd
CVE-2000-0283MEDIUMCVSS 6.4v6.2v6.3+6 more2000-04-12
CVE-2000-0283 [MEDIUM] CVE-2000-0283: The default installation of IRIX Performance Copilot allows remote attackers to access sensitive sys
The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.
nvd
CVE-2000-0245CRITICALCVSS 10.0PoCv5.2v5.3+4 more2000-03-27
CVE-2000-0245 [CRITICAL] CVE-2000-0245: Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.
Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.
nvd
CVE-2000-0207HIGHCVSS 7.5PoCv6.5v6.5.1+7 more2000-03-01
CVE-2000-0207 [HIGH] CVE-2000-0207: SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metach
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.
nvd
CVE-2000-1220CRITICALCVSS 10.0PoCv6.5v6.5.1+22 more2000-01-08
CVE-2000-1220 [CRITICAL] CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local us
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
nvd
CVE-2000-1221CRITICALCVSS 10.0PoCv6.5v6.5.1+22 more2000-01-08
CVE-2000-1221 [CRITICAL] CVE-2000-1221: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates b
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
nvd
CVE-2000-0013HIGHCVSS 7.2PoCv6.21999-12-31
CVE-2000-0013 [HIGH] CVE-2000-0013: IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in
IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.
nvd
CVE-1999-1102LOWCVSS 2.1≤ 5.21999-12-31
CVE-1999-1102 [LOW] CVE-1999-1102: lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
nvd