SgiCVEs & Vulnerabilities
259 CVEs affecting Sgi products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
Most Affected Products
Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.
The printers program in IRIX has a buffer overflow that gives root access to local users.
Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.
(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.
Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.
System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.
Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.
Buffer overflow in SGI IRIX mailx program.
Buffer overflow in statd allows root privileges.
SGI syserr program allows local users to corrupt files.
SGI permissions program allows local users to gain root privileges.
Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.
The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.
The handler CGI program in IRIX allows arbitrary command execution.
spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
root privileges via buffer overflow in login/scheme command on SGI IRIX systems.
root privileges via buffer overflow in ordist command on SGI IRIX systems.
root privileges via buffer overflow in df command on SGI IRIX systems.
root privileges via buffer overflow in pset command on SGI IRIX systems.
root privileges via buffer overflow in eject command on SGI IRIX systems.
root privileges via buffer overflow in xlock command on SGI IRIX systems.
IRIX fam service allows an attacker to obtain a list of all files on the server.
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
Command execution in Sun systems via buffer overflow in the at program.
getcwd() file descriptor leak in FTP.
Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.
IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.
Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.
addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.
addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.
SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.
inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.
Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.
webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.
Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
Buffer overflow in xlock program allows local users to execute commands as root.
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.
IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.
Csetup under IRIX allows arbitrary file creation or overwriting.
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.