Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.
Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.
Buffer overflow in SCO scohelp program allows remote attackers to execute commands.
UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.
The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into init before the privileged process is executed.
Buffer overflow in SCO su program allows local users to gain root access via a long username.
UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
Buffer overflow in UnixWare xauto program allows local users to gain root privilege.
Buffer overflow in SCO UnixWare Xsco command via a long argument.
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.