CVE-2002-0038 describes a denial-of-service vulnerability in the unified name service daemon (nsd) of SGI IRIX versions 6.5.4 through 6.5.11. Remote attackers can exploit a flaw in the cache-limiting function to force the cache to fill the disk, rendering the service unavailable. This vulnerability has a CVSS score of 5.0 (Medium), indicating a network-based attack with low complexity and no authentication required, leading to partial availability impact. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, the CVE has garnered significant community discussion with 10 mentions, suggesting some level of awareness. There is no indication of active exploitation or inclusion in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5.4CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.4:*:*:*:*:*:*:* | ||
6.5.5CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.5:*:*:*:*:*:*:* | ||
6.5.6CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.6:*:*:*:*:*:*:* | ||
6.5.7CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.7:*:*:*:*:*:*:* | ||
6.5.8CPE matchmatch criteria | cpe:2.3:o:sgi:irix:6.5.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.