Where
AND
-Infinity
0
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

First published (updated )
Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in SCO scohelp program allows remote attackers to execute commands.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into init before the privileged process is executed.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in SCO su program allows local users to gain root access via a long username.

First published (updated )
Severity
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C

UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in UnixWare xauto program allows local users to gain root privilege.

First published (updated )
Severity
7.2
Buffer Overflow
AV:L/AC:L/Au:N/C:C/I:C/A:C

Buffer overflow in SCO UnixWare Xsco command via a long argument.

First published (updated )
Severity
5.4
AV:N/AC:L/Au:N/C:C/I:C/A:C

Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:P/I:N/A:N

The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

First published (updated )
Severity
5
Buffer Overflow
AV:N/AC:L/Au:N/C:N/I:N/A:P

MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.

First published (updated )
Severity
3.6
AV:L/AC:L/Au:N/C:P/I:P/A:N

UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.

First published (updated )
Severity
3.6
AV:L/AC:L/Au:N/C:P/I:P/A:N

The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203