Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
188 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.29% | — | Osirix-viewer Osirix MDAI | 8/5/2025 | 17/6/2026 | Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Pixmeo Osirix MD WEB PortalAI | 8/5/2025 | 17/6/2026 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials. | |
| Aplazada | Alta (8.7) | 0.97% | — | Osirix-viewer Osirix MDAI | 8/5/2025 | 17/6/2026 | Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition. | |
| Modificada | Baja (1.9) | 0.35% | — | Osirix-viewer OsirixOsirix-viewer Osirix MD | 18/11/2013 | 16/6/2026 | The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key. | |
| Modificada | Alta (10) | 20% | — | HP Nfs/oncplusIBM AIXIBM ViosSGI Irix | 20/5/2010 | 16/6/2026 | Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format… | |
| Modificada | Alta (7.6) | 16% | — | MplayerSGI Irix | 18/9/2007 | 16/6/2026 | Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value. | |
| Modificada | Alta (7.2) | 0.83% | — | SGI Irix | 12/10/2005 | 16/6/2026 | runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin. | |
| Modificada | Alta (7.5) | 1.3% | — | SGI Irix | 21/9/2005 | 16/6/2026 | rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a… | |
| Modificada | Alta (7.5) | 1.3% | — | SGI Irix | 21/9/2005 | 16/6/2026 | Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities. | |
| Modificada | Baja (2.1) | 0.78% | — | SGI Irix | 2/5/2005 | 16/6/2026 | gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option. | |
| Modificada | Baja (2.1) | 0.69% | — | SGI Irix | 2/5/2005 | 16/6/2026 | gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error. | |
| Modificada | Alta (7.2) | 0.39% | — | SGI Irix | 14/1/2005 | 16/6/2026 | inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges. | |
| Modificada | Alta (10) | 1.7% | — | SGI Irix | 10/1/2005 | 16/6/2026 | Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors. | |
| Modificada | Media (5) | 0.88% | — | SGI Irix | 31/12/2004 | 16/6/2026 | The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged. | |
| Modificada | Media (5) | 2.4% | — | SGI Irix | 31/12/2004 | 16/6/2026 | Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows. | |
| Modificada | Alta (7.2) | 0.34% | — | SGI IrixAILibcprAI | 18/8/2004 | 16/6/2026 | cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process. | |
| Modificada | Baja (2.1) | 0.36% | — | SGI Irix | 6/8/2004 | 16/6/2026 | The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary." | |
| Modificada | Alta (7.2) | 0.34% | — | SGI Irix | 6/8/2004 | 16/6/2026 | The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory. | |
| Modificada | Baja (2.1) | 0.33% | — | SGI Irix | 6/8/2004 | 16/6/2026 | Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues." | |
| Modificada | Media (5) | 1.8% | — | SGI Irix | 7/7/2004 | 16/6/2026 | Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests. | |
| Modificada | Media (4.6) | 0.32% | — | SGI Irix | 5/5/2004 | 16/6/2026 | ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received. | |
| Modificada | Media (5) | 1.6% | — | SGI Irix | 5/5/2004 | 16/6/2026 | Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet. | |
| Modificada | Media (5) | 1.6% | — | SGI IrixAI | 2/4/2004 | 16/6/2026 | Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode. | |
| Modificada | Alta (7.5) | 1.5% | — | SGI Irix | 29/3/2004 | 16/6/2026 | Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled. | |
| Modificada | Media (5) | 1.6% | — | SGI Irix | 29/3/2004 | 16/6/2026 | Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors. |