SGI's vulnerability footprint spans a focused set of enterprise-grade systems software and performance-management tools, yet the products occupy a prominent position in high-performance computing and Unix environments. The vendor's disclosures frequently acquire public exploit code, reflecting the historical appeal of SGI systems to both researchers and threat actors in specialized computing contexts. Vulnerabilities affecting SGI recur across products such as IRIX, ProPack, and Performance Co-Pilot through a pattern of memory-safety and information-disclosure weaknesses—including buffer overflows, out-of-bounds reads, and bounds-checking failures—that are characteristic of legacy native-code infrastructure software. Defenders managing SGI systems or embedded Performance Co-Pilot instances should treat disclosed vulnerabilities as requiring prompt review and patching due to the availability of exploit tooling; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sgi over time
Signals from CVEs in this vendor scope (259 CVEs).
259 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0797HIGH Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as | Dec 12, 2001 | 10.0 | 88 | NO | YES |
CVE-2001-0800HIGH lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | Dec 6, 2001 | 10.0 | 78 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2002-1318HIGH Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the over | Dec 11, 2002 | 10.0 | 64 | NO | YES |
CVE-2001-0554HIGH Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You Th | Aug 14, 2001 | 10.0 | 60 | NO | YES |
CVE-1999-0009HIGH Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | Apr 8, 1998 | 10.0 | 54 | NO | YES |
CVE-2010-1039HIGH Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B | May 20, 2010 | 10.0 | 53 | NO | YES |
CVE-2001-0247HIGH Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_ | Jun 18, 2001 | 10.0 | 52 | NO | YES |
CVE-1999-0003HIGH Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd). | Apr 1, 1998 | 10.0 | 51 | NO | YES |
CVE-2004-0519MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication inform | Aug 18, 2004 | 6.8 | 46 | NO | YES |
Signals from CVEs in this vendor scope (259 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sgi.
Media articles that mention a CVE ID that affects a product developed by Sgi — matched by CVE ID, not by vendor name.