📦

unixware

Vendor: caldera

Actively Exploited 0 CISA KEV List
PoC / Exploits 21 Code Available
Total RCEs 2 Remote Access
Total CVEs 40 Total Indexed
Avg. EPSS 1.70% Exploit Prob.
Latest CVE CVE-2009-1552 May 06

Security Vulnerability Index

Page 3 / 4
10.0 CVSS

Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.

EPSS: 1.96%
10.0 CVSS

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

EPSS: 23.26%
7.2 CVSS

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

EPSS: 0.36%
7.2 CVSS

Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.

EPSS: 0.46%
7.5 CVSS

CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.

EPSS: 6.57%
7.2 CVSS

CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.

EPSS: 9.42%
10.0 CVSS
CVE-2002-0311
Exploit Found

Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

EPSS: 4.54%
7.2 CVSS
CVE-2002-0246
Exploit Found

Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.

EPSS: 0.98%
7.2 CVSS

CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.

EPSS: 0.35%
7.5 CVSS

Unknown vulnerability in CDE in Caldera OpenUnix 7.1.0, 7.1.1, and 8.0 allows an xterm session to gain privileges when the session is reused.

EPSS: 1.28%