SgiCVEs & Vulnerabilities

259 CVEs affecting Sgi products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

irix 2,246propack 86performance co-pilot 81samba 15mailx 9license oeo 3freeware 3mipspro compilers 2
CVE-1999-1120MEDIUMpoc

netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.

4 Jan 1997
4.6
CVSS
CVE-1999-1401MEDIUM

Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).

5 Dec 1996
4.6
CVSS
CVE-1999-0044HIGHpoc

fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.

3 Dec 1996
7.2
CVSS
CVE-1999-1384HIGHpoc

Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.

30 Oct 1996
7.2
CVSS
CVE-1999-0032HIGHpoc

Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.

25 Oct 1996
7.2
CVSS
CVE-1999-0234MEDIUM

Bash treats any character with a value of 255 as a command separator.

8 Oct 1996
4.6
CVSS
CVE-1999-0022HIGH

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

3 Jul 1996
7.8
CVSS
CVE-1999-0019MEDIUM

Delete or create a file via rpc.statd, due to invalid information.

24 Apr 1996
5.0
CVSS
CVE-1999-0078LOW

pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

18 Apr 1996
1.9
CVSS
CVE-1999-1319CRITICAL

Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.

3 Jan 1996
10.0
CVSS
CVE-1999-0208CRITICALpoc

rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

12 Dec 1995
10.0
CVSS
CVE-1999-0241CRITICAL

Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.

1 Nov 1995
10.0
CVSS
CVE-1999-0073CRITICAL

Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.

13 Oct 1995
10.0
CVSS
CVE-1999-1243MEDIUMpoc

SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.

3 Mar 1995
4.6
CVSS
CVE-1999-1022MEDIUMpoc

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

2 Oct 1994
6.2
CVSS
CVE-1999-1219HIGHpoc

Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.

11 Aug 1994
7.2
CVSS
CVE-1999-1494LOWpoc

colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.

9 Aug 1994
2.1
CVSS
CVE-1999-1468MEDIUM

rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.

22 Oct 1991
6.2
CVSS
CVE-1999-1554LOW

/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.

31 Oct 1990
2.1
CVSS
← PrevPage 6 / 6Next →