Skip to main content

Vendor archive

sco CVEs

Beta · best-effort

99 CVEs tagged to vendor sco10 Critical, 39 High, 35 Medium, 15 Low, 0 Unrated.

CVE-2004-0510

Published Dec 23, 2004

Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execm…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0511

Published Dec 23, 2004

Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0512

Published Dec 23, 2004

Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1082

Published Feb 3, 2004

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVSS 7.5 · High

CVE-2004-1124

Published Jan 14, 2004

Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0937

Published Dec 15, 2003

SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descripto…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0834

Published Dec 1, 2003

Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEAR…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0872

Published Nov 17, 2003

Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0791

Published Oct 7, 2003

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaS…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0742

Published Oct 6, 2003

SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from nc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0597

Published Aug 27, 2003

Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1998

Published Dec 31, 2002

Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0716

Published Jul 26, 2002

Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1508

Published Dec 31, 2001

Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1578

Published Dec 31, 2001

Unknown vulnerability in SCO OpenServer 5.0.6 and earlier allows local users to modify critical information such as certain CPU registers and segment descriptors.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1579

Published Dec 31, 2001

The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, which allows remote attackers to cause a denial of service.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 99 CVEsPage 2 of 4