Page 3 of 52 results (0.004 seconds)

CVSS: 7.1EPSS: 0%CPEs: 24EXPL: 0

02 Apr 2003 — fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file. fsr_efs en IRIX 6.5 permite a usuarios locales llevar a cabo actividades no autorizadas con ficheros mediante un ataque de enlace simbólico (symlink), posiblemente mediante el fichero .fsrlast • ftp://patches.sgi.com/support/free/security/advisories/20020903-01-P •

CVSS: 5.5EPSS: 0%CPEs: 23EXPL: 0

02 Apr 2003 — rpcbind in SGI IRIX, when using the -w command line switch, allows local users to overwrite arbitrary files via a symlink attack. • ftp://patches.sgi.com/support/free/security/advisories/20020903-01-P •

CVSS: 9.8EPSS: 96%CPEs: 165EXPL: 1

21 Mar 2003 — Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391. Desbordamiento de entero en la función xdrmem_getbytes(), y posiblemente otras funciones, de librerias XDR (representación de datos externos) derivadas de SunRPC, incluyendo l... • ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc •

CVSS: 9.8EPSS: 0%CPEs: 91EXPL: 0

03 Mar 2003 — The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. El emulador de terminal dtterm permite a atacantes modificar el título de la ventana mediante una cierta secuencia de carácter de escape, y a continuación insertarlo de nuevo en la linea de comandos del... • http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0093.html •

CVSS: 7.8EPSS: 0%CPEs: 23EXPL: 0

31 Dec 2002 — Buffer overflow in uux in eoe.sw.uucp package of SGI IRIX 6.5 through 6.5.17 allows local users to execute arbitrary code via unknown attack vectors. • ftp://patches.sgi.com/support/free/security/advisories/20020903-02-P •

CVSS: 9.1EPSS: 0%CPEs: 14EXPL: 0

31 Dec 2002 — The Video Control Panel on SGI O2/IRIX 6.5, when the Default Input is set to "Output Video", allows attackers to access a console session by running videoout then videoin. • ftp://patches.sgi.com/support/free/security/advisories/20020103-01-I •

CVSS: 5.5EPSS: 0%CPEs: 15EXPL: 0

31 Dec 2002 — SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information. • ftp://patches.sgi.com/support/free/security/advisories/20020902-01-I •

CVSS: 5.5EPSS: 0%CPEs: 23EXPL: 0

31 Dec 2002 — SGI IRIX 6.5 through 6.5.17 creates temporary desktop files with world-writable permissions, which allows local users to overwrite or corrupt those files. • ftp://patches.sgi.com/support/free/security/advisories/20020903-02-P •

CVSS: 5.5EPSS: 0%CPEs: 77EXPL: 2

31 Dec 2002 — The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network. • ftp://patches.sgi.com/support/free/security/advisories/20020901-01-A •

CVSS: 10.0EPSS: 1%CPEs: 59EXPL: 0

27 Dec 2002 — Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges. • ftp://patches.sgi.com/support/free/security/advisories/20030402-01-P •