Vulnerabilities > SGI

DATE CVE VULNERABILITY TITLE RISK
2004-08-18 CVE-2004-0234 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
10.0
2004-08-18 CVE-2004-0233 Local vulnerability in UTempter
Utempter allows device names that contain ..
local
low complexity
sgi utempter slackware
2.1
2004-08-18 CVE-2004-0232 Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
5.0
2004-08-18 CVE-2004-0231 Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."
local
low complexity
midnight-commander sgi gentoo slackware
2.1
2004-08-18 CVE-2004-0226 Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
critical
10.0
2004-08-18 CVE-2004-0134 Privilege Escalation vulnerability in IRIX Checkpoint and Restart libcpr Library Loading
cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.
local
low complexity
sgi
7.2
2004-08-06 CVE-2004-0639 HTML Injection vulnerability in SquirrelMail From Email Header
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.
6.8
2004-08-06 CVE-2004-0418 serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
network
low complexity
cvs openpkg sgi gentoo openbsd
critical
10.0
2004-08-06 CVE-2004-0417 Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
network
low complexity
cvs openpkg sgi gentoo openbsd
5.0
2004-08-06 CVE-2004-0416 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
network
low complexity
cvs openpkg sgi gentoo openbsd CWE-119
critical
10.0