Vulnerabilities (CVE)

Filtered by vendor Sco Subscribe
Filtered by product Unixware
Total 66 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0937 1 Sco 2 Open Unix, Unixware 2025-04-03 4.6 MEDIUM N/A
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
CVE-2005-2934 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
Unspecified vulnerability in ptrace in SCO UnixWare 7.1.3 and 7.1.4 allows local users to gain privileges via unspecified vectors.
CVE-1999-0988 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.
CVE-2000-0224 1 Sco 1 Unixware 2025-04-03 1.2 LOW N/A
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
CVE-1999-0866 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
Buffer overflow in UnixWare xauto program allows local users to gain root privilege.
CVE-2000-0215 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.
CVE-1999-1252 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.
CVE-2000-0003 1 Sco 1 Unixware 2025-04-03 10.0 HIGH N/A
Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.
CVE-1999-0864 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
CVE-2003-0914 9 Compaq, Freebsd, Hp and 6 more 10 Tru64, Freebsd, Hp-ux and 7 more 2025-04-03 4.3 MEDIUM N/A
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
CVE-2005-2927 1 Sco 1 Unixware 2025-04-03 7.2 HIGH N/A
Stack-based buffer overflow in ppp in SCO Unixware 7.1.3 and 7.1.4, and possibly earlier versions, allows local users to execute arbitrary code via a long argument to the (1) prompt or (2) defprompt command.
CVE-2006-4655 2 Sco, Sun 2 Unixware, Solaris 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.
CVE-2005-0134 1 Sco 1 Unixware 2025-04-03 4.6 MEDIUM N/A
The X server in SCO UnixWare 7.1.1, 7.1.3, and 7.1.4 does not properly create socket directories in /tmp, which could allow attackers to hijack local sockets.
CVE-1999-0851 3 Ibm, Sco, Sun 4 Aix, Openserver, Unixware and 1 more 2025-04-03 2.1 LOW N/A
Denial of service in BIND named via naptr.
CVE-1999-0017 9 Caldera, Freebsd, Gnu and 6 more 11 Openlinux, Freebsd, Inet and 8 more 2025-04-03 7.5 HIGH N/A
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
CVE-2000-0351 1 Sco 1 Unixware 2025-04-03 4.6 MEDIUM N/A
Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages.
CVE-2000-0842 1 Sco 1 Unixware 2025-04-03 5.0 MEDIUM N/A
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0019 7 Data General, Ibm, Ncr and 4 more 10 Dg Ux, Aix, Mp-ras and 7 more 2025-04-03 5.0 MEDIUM N/A
Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0825 1 Sco 1 Unixware 2025-04-03 3.6 LOW N/A
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
CVE-2001-1579 1 Sco 2 Open Unix, Unixware 2025-04-03 5.0 MEDIUM N/A
The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, which allows remote attackers to cause a denial of service.