Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
–

188 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.29%—Osirix-viewer Osirix MDAI8/5/202517/6/2026
Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash.
AplazadaCrítica (9.3)0.30%—Pixmeo Osirix MD WEB PortalAI8/5/202517/6/2026
The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.
AplazadaAlta (8.7)0.97%—Osirix-viewer Osirix MDAI8/5/202517/6/2026
Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.
ModificadaBaja (1.9)0.35%—Osirix-viewer OsirixOsirix-viewer Osirix MD18/11/201316/6/2026
The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.
ModificadaAlta (10)20%—HP Nfs/oncplusIBM AIXIBM ViosSGI Irix20/5/201016/6/2026
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format…
ModificadaAlta (7.6)16%—MplayerSGI Irix18/9/200716/6/2026
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
ModificadaAlta (7.2)0.83%—SGI Irix12/10/200516/6/2026
runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.
ModificadaAlta (7.5)1.3%—SGI Irix21/9/200516/6/2026
rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a…
ModificadaAlta (7.5)1.3%—SGI Irix21/9/200516/6/2026
Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.
ModificadaBaja (2.1)0.78%—SGI Irix2/5/200516/6/2026
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
ModificadaBaja (2.1)0.69%—SGI Irix2/5/200516/6/2026
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.
ModificadaAlta (7.2)0.39%—SGI Irix14/1/200516/6/2026
inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.
ModificadaAlta (10)1.7%—SGI Irix10/1/200516/6/2026
Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.
ModificadaMedia (5)0.88%—SGI Irix31/12/200416/6/2026
The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.
ModificadaMedia (5)2.4%—SGI Irix31/12/200416/6/2026
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.
ModificadaAlta (7.2)0.34%—SGI IrixAILibcprAI18/8/200416/6/2026
cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process.
ModificadaBaja (2.1)0.36%—SGI Irix6/8/200416/6/2026
The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary."
ModificadaAlta (7.2)0.34%—SGI Irix6/8/200416/6/2026
The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.
ModificadaBaja (2.1)0.33%—SGI Irix6/8/200416/6/2026
Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues."
ModificadaMedia (5)1.8%—SGI Irix7/7/200416/6/2026
Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.
ModificadaMedia (4.6)0.32%—SGI Irix5/5/200416/6/2026
ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.
ModificadaMedia (5)1.6%—SGI Irix5/5/200416/6/2026
Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.
ModificadaMedia (5)1.6%—SGI IrixAI2/4/200416/6/2026
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.
ModificadaAlta (7.5)1.5%—SGI Irix29/3/200416/6/2026
Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.
ModificadaMedia (5)1.6%—SGI Irix29/3/200416/6/2026
Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.