Vulnerabilities (CVE)

Filtered by vendor Sco Subscribe
Filtered by product Openserver
Total 72 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0851 3 Ibm, Sco, Sun 4 Aix, Openserver, Unixware and 1 more 2024-02-28 2.1 LOW N/A
Denial of service in BIND named via naptr.
CVE-2004-0079 23 4d, Apple, Avaya and 20 more 66 Webstar, Mac Os X, Mac Os X Server and 63 more 2024-02-28 5.0 MEDIUM 7.5 HIGH
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
CVE-1999-0835 3 Ibm, Sco, Sun 4 Aix, Openserver, Unixware and 1 more 2024-02-28 10.0 HIGH N/A
Denial of service in BIND named via malformed SIG records.
CVE-1999-0024 6 Bsdi, Ibm, Isc and 3 more 12 Bsd Os, Aix, Bind and 9 more 2024-02-28 5.0 MEDIUM N/A
DNS cache poisoning via BIND, by predictable query IDs.
CVE-2004-0390 1 Sco 1 Openserver 2024-02-28 7.5 HIGH N/A
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.
CVE-2001-0578 1 Sco 1 Openserver 2024-02-28 4.6 MEDIUM N/A
Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.
CVE-1999-0096 3 Bsdi, Freebsd, Sco 4 Bsd Os, Freebsd, Internet Faststart and 1 more 2024-02-28 5.0 MEDIUM N/A
Sendmail decode alias can be used to overwrite sensitive files.
CVE-2004-0512 1 Sco 1 Openserver 2024-02-28 2.1 LOW N/A
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.
CVE-2003-0597 1 Sco 1 Openserver 2024-02-28 7.2 HIGH N/A
Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.
CVE-1999-0345 4 Freebsd, Ibm, Sco and 1 more 7 Freebsd, Aix, Sng and 4 more 2024-02-28 5.0 MEDIUM N/A
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
CVE-2001-0896 1 Sco 1 Openserver 2024-02-28 5.0 MEDIUM N/A
Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO.
CVE-1999-1209 1 Sco 2 Open Desktop, Openserver 2024-02-28 7.2 HIGH N/A
Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.
CVE-2001-1508 1 Sco 1 Openserver 2024-02-28 4.6 MEDIUM N/A
Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.
CVE-2001-0579 1 Sco 1 Openserver 2024-02-28 7.5 HIGH N/A
lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.
CVE-1999-1185 1 Sco 5 Cmw, Internet Faststart, Open Desktop and 2 more 2024-02-28 7.2 HIGH N/A
Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.
CVE-2000-0158 1 Sco 1 Openserver 2024-02-28 7.5 HIGH N/A
Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.
CVE-1999-0697 1 Sco 1 Openserver 2024-02-28 7.2 HIGH N/A
SCO Doctor allows local users to gain root privileges through a Tools option.
CVE-1999-0476 1 Sco 1 Openserver 2024-02-28 7.2 HIGH N/A
A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.
CVE-2003-0872 1 Sco 1 Openserver 2024-02-28 2.1 LOW N/A
Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.
CVE-1999-0010 8 Data General, Ibm, Isc and 5 more 11 Dg Ux, Aix, Bind and 8 more 2024-02-28 5.0 MEDIUM N/A
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.