Vulnerabilities > Cray

DATE CVE VULNERABILITY TITLE RISK
2014-12-27 CVE-2014-0748 Improper Input Validation vulnerability in Cray Linux Environment 5.1
apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.
local
low complexity
cray CWE-20
7.2
2006-01-11 CVE-2006-0178 Local Command Line Argument Buffer Overflow vulnerability in Cray Unicos 9.0.2.2
Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.
local
low complexity
cray
7.2
2006-01-11 CVE-2006-0177 Local Command Line Argument Buffer Overflow vulnerability in Cray Unicos 9.0.2.2
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.
local
low complexity
cray
7.2
2003-03-25 CVE-2003-0028 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
network
low complexity
gnu mit openafs sgi cray freebsd hp ibm openbsd sun
7.5
2002-01-31 CVE-2001-0891 Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.
local
low complexity
sgi cray
7.2
1999-12-31 CVE-1999-1300 Unspecified vulnerability in Cray Unicos 6.0/6.1
Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.
local
low complexity
cray
3.6
1999-07-19 CVE-1999-0692 The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.
network
low complexity
sgi cray
critical
10.0
1997-02-13 CVE-1999-0041 Buffer overflow in NLS (Natural Language Service).
network
low complexity
gnu cray ibm slackware redhat
7.5
1995-10-19 CVE-1999-0099 Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
network
low complexity
sun cray convex bsdi ibm
critical
10.0
1991-10-22 CVE-1999-1468 rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.
local
high complexity
next sgi cray sun
6.2