Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 5.7% | — | SGI Performance Co-pilot | 27/8/2012 | 16/6/2026 | libpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a PDU with the numcreds field value greater than the number of actual elements to the __pmDecodeCreds function in p_creds.c; (2) the string byte number value to the… | |
| Modificada | Alta (10) | 20% | 💥 Exploit | HP Nfs/oncplusIBM AIXIBM ViosSGI Irix | 20/5/2010 | 16/6/2026 | Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format… | |
| Modificada | Alta (7.6) | 16% | 💥 Exploit | MplayerSGI Irix | 18/9/2007 | 16/6/2026 | Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value. | |
| Modificada | Baja (1.2) | 0.28% | — | SGI Propack | 6/2/2007 | 16/6/2026 | SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Alta (7.2) | 0.83% | 💥 Exploit | SGI Irix | 12/10/2005 | 16/6/2026 | runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin. | |
| Modificada | Alta (7.5) | 1.3% | — | SGI Irix | 21/9/2005 | 16/6/2026 | Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities. | |
| Modificada | Alta (7.5) | 1.3% | — | SGI Irix | 21/9/2005 | 16/6/2026 | rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a… | |
| Modificada | Alta (7.2) | 0.32% | — | SGI Propack | 12/7/2005 | 16/6/2026 | Unknown vulnerability in arshell in the Array Service (arrayd) for SGI ProPack 3 with SP 5 and 6, and SGI ProPack 4, allows local users to execute arbitrary shells as root on other hosts in the cluster or array. | |
| Modificada | Baja (2.1) | 0.69% | 💥 Exploit | SGI Irix | 2/5/2005 | 16/6/2026 | gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error. | |
| Modificada | Baja (2.1) | 0.78% | 💥 Exploit | SGI Irix | 2/5/2005 | 16/6/2026 | gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option. | |
| Modificada | Alta (7.5) | 4.4% | — | GraphicsmagickImagemagickSGI PropackDebian Linux+2 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers. | |
| Modificada | Alta (7.5) | 3.0% | — | Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+18 | 27/4/2005 | 16/6/2026 | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities. | |
| Modificada | Media (5) | 1.9% | — | PHPSGI PropackConectiva LinuxApple MAC OS X+3 | 14/4/2005 | 16/6/2026 | exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion. | |
| Modificada | Media (5) | 1.8% | — | ImagemagickSGI Propack | 23/3/2005 | 16/6/2026 | ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag. | |
| Modificada | Media (5) | 1.7% | — | ImagemagickSGI Propack | 23/3/2005 | 16/6/2026 | Unknown vulnerability in ImageMagick before 6.1.8 allows remote attackers to cause a denial of service (application crash) via a crafted PSD file. | |
| Modificada | Media (5) | 2.4% | — | Ipsec-toolsKame RacoonSGI PropackAltlinux ALT Linux+3 | 14/3/2005 | 16/6/2026 | The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | |
| Modificada | Alta (7.5) | 4.5% | — | LesstifSGI PropackX.org X11r6Xfree86 Project X11r6+7 | 2/3/2005 | 16/6/2026 | scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow. | |
| Modificada | Baja (2.1) | 1.3% | 💥 Exploit | Larry Wall PerlSGI PropackIBM AIXRedhat Enterprise Linux+5 | 7/2/2005 | 16/6/2026 | Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree. | |
| Modificada | Media (5) | 4.9% | — | SambaSGI SambaConectiva LinuxGentoo Linux+4 | 27/1/2005 | 16/6/2026 | The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters. | |
| Modificada | Media (4.6) | 1.2% | — | GNU EnscriptSGI PropackRedhat Fedora CoreSuse Linux | 21/1/2005 | 16/6/2026 | The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters. | |
| Modificada | Alta (7.2) | 0.39% | — | SGI Irix | 14/1/2005 | 16/6/2026 | inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges. | |
| Modificada | Alta (10) | 1.7% | — | SGI Irix | 10/1/2005 | 16/6/2026 | Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors. |