VendorsScounixwareall versions
Vulnerabilities

Sco Unixware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

66CVEs
CVE-2003-0658
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
Published 2003-09-03 · Modified
5.0EPSS 0.021
CVE-2000-0842
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Published 2000-10-18 · Modified
5.0EPSS 0.019
CVE-1999-0019
Delete or create a file via rpc.statd, due to invalid information.
Published 1999-09-29 · Modified
5.0EPSS 0.017
CVE-2004-1039
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.
Published 2005-01-19 · Modified
5.0EPSS 0.016
CVE-2000-0173
Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.
Published 2000-03-22 · Modified
5.0EPSS 0.013
CVE-2001-1579
The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, which allows remote attackers to cause a denial of service.
Published 2005-08-05 · Modified
5.0EPSS 0.012
CVE-2000-0307
Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.
Published 2001-05-07 · Modified
5.0EPSS 0.011
CVE-2000-0349
Vulnerability in the passthru driver in SCO UnixWare 7.1.0 allows an attacker to cause a denial of service.
Published 2001-05-07 · Modified
5.0EPSS 0.011
CVE-2008-1343
Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in SCO UnixWare 7.1.4 allows local users to gain privileges via unknown vectors.
Published 2008-03-17 · Modified
4.91 PoCEPSS 0.008
CVE-2006-4655
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.
Published 2006-09-09 · Modified
4.64 PoCEPSS 0.009
CVE-2005-3903
Buffer overflow in uidadmin in SCO Unixware 7.1.3 and 7.1.4 allows local users to execute arbitrary code via a -S (scheme) argument that specifies a large file, a different vulnerability than CVE-2001-1063.
Published 2005-12-14 · Modified
4.6EPSS 0.005
CVE-2002-1323
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
Published 2004-09-01 · Modified
4.6EPSS 0.005
CVE-2003-0937
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
Published 2003-11-18 · Modified
4.6EPSS 0.004
CVE-2004-1124
Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.
Published 2005-01-29 · Modified
4.6EPSS 0.003
CVE-2005-0134
The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.
Published 2005-05-18 · Modified
4.6EPSS 0.003
CVE-2000-0029
UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.
Published 2000-03-22 · Modified
4.6EPSS 0.003
CVE-2000-0351
Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages.
Published 2001-05-07 · Modified
4.6EPSS 0.003
CVE-2003-0914
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
Published 2003-12-02 · Modified
4.3EPSS 0.032
CVE-1999-0828
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.
Published 2000-02-04 · Modified
3.63 PoCEPSS 0.008
CVE-1999-0825
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
Published 2000-02-04 · Modified
3.61 PoCEPSS 0.006
CVE-2004-0996
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
Published 2004-12-01 · Modified
2.12 PoCEPSS 0.011
CVE-2005-2132
RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests.
Published 2005-08-03 · Modified
2.1EPSS 0.005
CVE-1999-0851
Denial of service in BIND named via naptr.
Published 2000-01-04 · Modified
2.1EPSS 0.004
CVE-1999-0078
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
Published 2000-02-04 · Modified
1.9EPSS 0.009
CVE-2000-0154
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.
Published 2000-02-23 · Modified
1.21 PoCEPSS 0.008
CVE-2000-0224
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
Published 2000-04-10 · Modified
1.21 PoCEPSS 0.006
← Prev2 / 2