
CVE-2001-0800 – Irix LPD tagprinter - Command Execution
https://notcve.org/view.php?id=CVE-2001-0800
22 Nov 2001 — lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. • https://www.exploit-db.com/exploits/10033 •

CVE-2001-0331
https://notcve.org/view.php?id=CVE-2001-0331
27 Jun 2001 — Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands. • ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P •

CVE-2001-0247 – FreeBSD 2.2-4.2 / NetBSD 1.2-4.5 / OpenBSD 2.x - FTPd 'glob()' Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0247
24 May 2001 — Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3. • https://www.exploit-db.com/exploits/20731 •

CVE-2001-0249
https://notcve.org/view.php?id=CVE-2001-0249
24 May 2001 — Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings. • http://www.cert.org/advisories/CA-2001-07.html • CWE-131: Incorrect Calculation of Buffer Size •

CVE-2000-0844 – Immunix OS 6.2 - LC glibc format string
https://notcve.org/view.php?id=CVE-2000-0844
14 Nov 2000 — Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/20187 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2000-0799 – IRIX 6.5.x - '/usr/lib/InPerson/inpview' Race Condition
https://notcve.org/view.php?id=CVE-2000-0799
20 Oct 2000 — inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file. • https://www.exploit-db.com/exploits/20130 •

CVE-2000-0733 – IRIX 5.2/5.3/6.x - TelnetD Environment Variable Format String
https://notcve.org/view.php?id=CVE-2000-0733
13 Oct 2000 — Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request. • https://www.exploit-db.com/exploits/20149 •

CVE-2000-0283
https://notcve.org/view.php?id=CVE-2000-0283
12 Apr 2000 — The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon. • http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html •

CVE-2000-0207 – SGI InfoSearch 1.0 / SGI IRIX 6.5.x - fname
https://notcve.org/view.php?id=CVE-2000-0207
01 Mar 2000 — SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. • https://www.exploit-db.com/exploits/19788 •

CVE-2000-1220 – BSD / Linux - 'lpr' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2000-1220
08 Jan 2000 — The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file. • https://www.exploit-db.com/exploits/325 •