Sco Open Unix vulnerabilities
5 known vulnerabilities affecting sco/open_unix.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2003-0937MEDIUMCVSS 4.6v8.02003-12-15
CVE-2003-0937 [MEDIUM] CVE-2003-0937: SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as"
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
nvd
CVE-2003-0834HIGHCVSS 7.2PoCv8.02003-12-01
CVE-2003-0834 [HIGH] CVE-2003-0834: Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modi
Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.
nvd
CVE-2002-1998HIGHCVSS 7.5v8.0.02002-12-31
CVE-2002-1998 [HIGH] CVE-2002-1998: Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to exe
Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21).
nvd
CVE-2002-1323MEDIUMCVSS 4.6v8.02002-12-11
CVE-2002-1323 [MEDIUM] CVE-2002-1323: Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
nvd
CVE-2001-1579MEDIUMCVSS 5.0v8.0.02001-12-31
CVE-2001-1579 [MEDIUM] CVE-2001-1579: The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain st
The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, which allows remote attackers to cause a denial of service.
nvd