VendorsScoopenserverall versions
Vulnerabilities

Sco Santa Cruz Operation (SCO) OpenServer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2004-0081
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Published 2004-03-18 · Modified
5.0EPSS 0.072
CVE-1999-0024
DNS cache poisoning via BIND, by predictable query IDs.
Published 1999-09-29 · Modified
5.0EPSS 0.050
CVE-2005-3626
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
Published 2006-01-06 · Modified
5.0EPSS 0.034
CVE-1999-0010
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Published 1999-09-29 · Modified
5.0EPSS 0.024
CVE-2005-3624
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
Published 2006-01-06 · Modified
5.0EPSS 0.023
CVE-2002-1199
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
Published 2004-09-01 · Modified
5.0EPSS 0.022
CVE-1999-0019
Delete or create a file via rpc.statd, due to invalid information.
Published 1999-09-29 · Modified
5.0EPSS 0.017
CVE-2001-0896
Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO.
Published 2002-06-25 · Modified
5.0EPSS 0.016
CVE-2004-1039
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.
Published 2005-01-19 · Modified
5.0EPSS 0.016
CVE-1999-0345
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
Published 2000-02-04 · Modified
5.0EPSS 0.013
CVE-1999-0096
Sendmail decode alias can be used to overwrite sensitive files.
Published 1999-09-29 · Modified
5.0EPSS 0.013
CVE-2000-0307
Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.
Published 2001-05-07 · Modified
5.0EPSS 0.011
CVE-2005-0993
Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument.
Published 2005-04-07 · Modified
4.61 PoCEPSS 0.011
CVE-2001-0575
Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut.
Published 2001-07-27 · Modified
4.61 PoCEPSS 0.007
CVE-2001-0578
Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.
Published 2001-07-27 · Modified
4.61 PoCEPSS 0.007
CVE-2001-0576
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.
Published 2001-07-27 · Modified
4.61 PoCEPSS 0.007
CVE-1999-0129
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Published 1999-09-29 · Modified
4.6EPSS 0.006
CVE-2001-0588
sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.
Published 2001-07-27 · Modified
4.6EPSS 0.005
CVE-2001-1508
Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.
Published 2005-07-14 · Modified
4.6EPSS 0.005
CVE-2005-2926
Stack-based buffer overflow in (1) backupsh and (2) authsh in SCO Openserver 5.0.7 allows local users to execute arbitrary code via a long HOME environment variable.
Published 2005-10-25 · Modified
4.6EPSS 0.004
CVE-2005-0351
Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.
Published 2005-04-09 · Modified
4.6EPSS 0.004
CVE-2001-1148
Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.
Published 2002-03-15 · Modified
4.6EPSS 0.004
CVE-2004-1124
Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.
Published 2005-01-29 · Modified
4.6EPSS 0.003
CVE-2001-0627
vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.
Published 2002-03-09 · Modified
3.7EPSS 0.004
CVE-2004-0511
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.
Published 2004-10-28 · Modified
2.11 PoCEPSS 0.010
CVE-1999-0893
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
Published 2000-03-22 · Modified
2.11 PoCEPSS 0.007
CVE-2004-0512
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.
Published 2004-10-28 · Modified
2.1EPSS 0.005
CVE-1999-0851
Denial of service in BIND named via naptr.
Published 2000-01-04 · Modified
2.1EPSS 0.004
CVE-2000-0147
snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.
Published 2000-02-16 · Modified
2.1EPSS 0.004
CVE-2003-0872
Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.
Published 2003-10-25 · Modified
2.1EPSS 0.003
CVE-2001-1578
Unknown vulnerability in SCO OpenServer 5.0.6 and earlier allows local users to modify critical information such as certain CPU registers and segment descriptors.
Published 2005-08-05 · Modified
2.1EPSS 0.003
CVE-1999-0078
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
Published 2000-02-04 · Modified
1.9EPSS 0.009
← Prev2 / 2