Vulnerabilities > SGI > Irix > 6.5.3

DATE CVE VULNERABILITY TITLE RISK
2003-08-27 CVE-2003-0575 Privilege Escalation vulnerability in SGI IRIX NSD AUTH_UNIX GID List
Heap-based buffer overflow in the name services daemon (nsd) in SGI IRIX 6.5.x through 6.5.21f, and possibly earlier versions, allows attackers to gain root privileges via the AUTH_UNIX gid list.
network
low complexity
sgi
critical
10.0
2003-08-18 CVE-2003-0574 Unspecified vulnerability in SGI Irix
Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.
local
low complexity
sgi
7.2
2003-08-18 CVE-2003-0573 Remote Security vulnerability in IRIX
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.
network
low complexity
sgi
5.0
2003-08-18 CVE-2003-0572 Denial-Of-Service vulnerability in IRIX
Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).
network
low complexity
sgi
5.0
2003-08-18 CVE-2003-0177 Local Security vulnerability in IRIX
SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.
local
low complexity
sgi
4.6
2003-08-18 CVE-2003-0176 Denial-Of-Service vulnerability in IRIX
The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.
network
low complexity
sgi
5.0
2003-05-12 CVE-2003-0174 Origin Validation Error vulnerability in SGI Irix
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
network
low complexity
sgi CWE-346
critical
9.8
2003-05-05 CVE-2003-0173 xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.
local
low complexity
xfsdump sgi
7.2
2003-04-02 CVE-2002-1518 Unspecified vulnerability in SGI Irix
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories.
local
low complexity
sgi
3.6
2003-04-02 CVE-2002-1517 Unspecified vulnerability in SGI Freeware and Irix
fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file.
local
low complexity
sgi
4.6