Vulnerabilities > SGI

DATE CVE VULNERABILITY TITLE RISK
2004-08-18 CVE-2004-0233 Local vulnerability in UTempter
Utempter allows device names that contain ..
local
low complexity
sgi utempter slackware
2.1
2004-08-18 CVE-2004-0232 Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
5.0
2004-08-18 CVE-2004-0231 Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."
local
low complexity
midnight-commander sgi gentoo slackware
2.1
2004-08-18 CVE-2004-0226 Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
critical
10.0
2004-08-18 CVE-2004-0134 Privilege Escalation vulnerability in IRIX Checkpoint and Restart libcpr Library Loading
cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.
local
low complexity
sgi
7.2
2004-08-06 CVE-2004-0639 HTML Injection vulnerability in SquirrelMail From Email Header
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
6.8
2004-08-06 CVE-2004-0418 serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
network
low complexity
cvs openpkg sgi gentoo openbsd
critical
10.0
2004-08-06 CVE-2004-0417 Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
network
low complexity
cvs openpkg sgi gentoo openbsd
5.0
2004-08-06 CVE-2004-0416 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
network
low complexity
cvs openpkg sgi gentoo openbsd CWE-119
critical
10.0
2004-08-06 CVE-2004-0414 CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
network
low complexity
cvs openpkg sgi gentoo openbsd
critical
10.0