Vulnerabilities (CVE)

Filtered by vendor Sco Subscribe
Filtered by product Unixware
Total 66 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0937 1 Sco 2 Open Unix, Unixware 2024-02-14 4.6 MEDIUM N/A
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
CVE-2000-0224 1 Sco 1 Unixware 2023-11-07 1.2 LOW N/A
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
CVE-2000-0154 1 Sco 1 Unixware 2023-11-07 1.2 LOW N/A
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.
CVE-1999-0864 1 Sco 1 Unixware 2023-11-07 7.2 HIGH N/A
UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
CVE-1999-0836 1 Sco 1 Unixware 2023-11-07 10.0 HIGH N/A
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
CVE-2003-0658 2 Caldera, Sco 4 Openlinux Server, Openlinux Workstation, Openserver and 1 more 2022-08-17 5.0 MEDIUM N/A
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
CVE-1999-0988 1 Sco 1 Unixware 2022-08-17 7.2 HIGH N/A
UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.
CVE-1999-0942 1 Sco 1 Unixware 2022-08-17 7.2 HIGH N/A
UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.
CVE-1999-0845 1 Sco 1 Unixware 2022-08-17 7.2 HIGH N/A
Buffer overflow in SCO su program allows local users to gain root access via a long username.
CVE-1999-0830 1 Sco 1 Unixware 2022-08-17 7.2 HIGH N/A
Buffer overflow in SCO UnixWare Xsco command via a long argument.
CVE-1999-0368 7 Caldera, Debian, Proftpd Project and 4 more 8 Openlinux, Debian Linux, Proftpd and 5 more 2022-08-17 10.0 HIGH N/A
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
CVE-1999-0078 10 Bsdi, Freebsd, Hp and 7 more 11 Bsd Os, Freebsd, Hp-ux and 8 more 2022-08-17 1.9 LOW N/A
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
CVE-1999-0033 5 Ibm, Ncr, Sco and 2 more 7 Aix, Mp-ras, Open Desktop and 4 more 2022-08-17 7.2 HIGH N/A
Command execution in Sun systems via buffer overflow in the at program.
CVE-1999-0024 6 Bsdi, Ibm, Isc and 3 more 12 Bsd Os, Aix, Bind and 9 more 2022-08-17 5.0 MEDIUM N/A
DNS cache poisoning via BIND, by predictable query IDs.
CVE-1999-0023 6 Bsdi, Freebsd, Ibm and 3 more 10 Bsd Os, Freebsd, Aix and 7 more 2022-08-17 7.2 HIGH N/A
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
CVE-1999-0017 9 Caldera, Freebsd, Gnu and 6 more 11 Openlinux, Freebsd, Inet and 8 more 2022-08-17 7.5 HIGH N/A
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
CVE-2004-1307 10 Apple, Avaya, Conectiva and 7 more 19 Mac Os X, Mac Os X Server, Call Management System Server and 16 more 2018-10-30 7.5 HIGH N/A
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
CVE-1999-0835 3 Ibm, Sco, Sun 4 Aix, Openserver, Unixware and 1 more 2018-10-30 10.0 HIGH N/A
Denial of service in BIND named via malformed SIG records.
CVE-2003-0914 9 Compaq, Freebsd, Hp and 6 more 10 Tru64, Freebsd, Hp-ux and 7 more 2018-10-30 4.3 MEDIUM N/A
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
CVE-1999-0851 3 Ibm, Sco, Sun 4 Aix, Openserver, Unixware and 1 more 2018-10-30 2.1 LOW N/A
Denial of service in BIND named via naptr.