Skip to main content

Vendor archive

caldera CVEs

Beta · best-effort

71 CVEs tagged to vendor caldera14 Critical, 36 High, 14 Medium, 7 Low, 0 Unrated.

CVE-2014-2936

Published May 8, 2014

The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2935

Published May 8, 2014

costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLR…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2934

Published May 8, 2014

Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/pri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2933

Published May 8, 2014

Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0884

Published Oct 4, 2002

Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating systems, allows remote attackers to execut…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0885

Published Oct 4, 2002

Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arb…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0887

Published Oct 4, 2002

scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-0911

Published Oct 4, 2002

Caldera Volution Manager 1.1 stores the Directory Administrator password in cleartext in the slapd.conf file, which could allow local users to gain privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0981

Published Sep 24, 2002

Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0987

Published Sep 24, 2002

X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0988

Published Sep 24, 2002

Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-0517

Published Aug 12, 2002

Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0827

Published Aug 12, 2002

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0442

Published Jul 26, 2002

Buffer overflow in dlvr_audit for Caldera OpenServer 5.0.5 and 5.0.6 allows local users to gain root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0311

Published May 31, 2002

Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-0246

Published May 29, 2002

Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to re…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1570

Published May 1, 2002

Buffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 71 CVEsPage 1 of 3