Caldera's vulnerability profile centers on its open-source and commercial Unix and Linux operating systems, including OpenLinux, UnixWare, and OpenUnix variants, which occupied a notable niche in enterprise and embedded deployment during their active lifecycle. Despite a modest product count, the vendor's presence in the vulnerability landscape reflects the widespread adoption and longevity of these systems, particularly in server and embedded contexts where patching cycles were protracted. The recurring weakness classes cluster around injection vulnerabilities—OS command injection, code injection, SQL injection, and path traversal—alongside unclassified placeholder entries, patterns typical of systems with complex service architectures and legacy application interfaces. A notable tendency toward public exploit availability distinguishes this vendor's disclosures, reflecting the appeal of these systems to security researchers and attackers targeting production Unix infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Caldera over time
Signals from CVEs in this vendor scope (82 CVEs).
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0917HIGH Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | Dec 19, 2000 | 10.0 | 84 | NO | YES |
CVE-1999-0368HIGH Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Feb 9, 1999 | 10.0 | 60 | NO | YES |
CVE-1999-0002HIGH Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. | Oct 12, 1998 | 10.0 | 56 | NO | YES |
CVE-1999-0043CRITICAL Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. | Dec 4, 1996 | 9.8 | 55 | NO | NO |
CVE-1999-0009HIGH Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | Apr 8, 1998 | 10.0 | 54 | NO | YES |
CVE-2000-0844HIGH Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun | Nov 14, 2000 | 10.0 | 44 | NO | YES |
CVE-2000-0491HIGH Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY | May 24, 2000 | 10.0 | 44 | NO | YES |
CVE-1999-0042HIGH Buffer overflow in University of Washington's implementation of IMAP and POP servers. | Apr 7, 1997 | 10.0 | 44 | NO | YES |
CVE-2002-0679HIGH Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREA | Sep 5, 2002 | 10.0 | 42 | NO | NO |
CVE-1999-0879HIGH Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. | Oct 1, 1999 | 10.0 | 39 | NO | YES |
Signals from CVEs in this vendor scope (82 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Caldera.
Media articles that mention a CVE ID that affects a product developed by Caldera — matched by CVE ID, not by vendor name.