CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. |
getcwd() file descriptor leak in FTP. |
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack. |
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. |
Bash treats any character with a value of 255 as a command separator. |
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files. |
ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames. |
SGI permissions program allows local users to gain root privileges. |
SGI mediad program allows local users to gain root access. |
Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges. |
Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server. |
The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges. |
Buffer overflow in uum program for Canna input system allows local users to gain root privileges. |
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges. |
IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option. |
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program. |
Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable. |
SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities. |
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times. |