Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Caldera

First CVE: Oct 8, 1996Active for: 30 yearsTotal CVEs: 82
54.0
VTI Score
TOP TARGET

Caldera's vulnerability profile centers on its open-source and commercial Unix and Linux operating systems, including OpenLinux, UnixWare, and OpenUnix variants, which occupied a notable niche in enterprise and embedded deployment during their active lifecycle. Despite a modest product count, the vendor's presence in the vulnerability landscape reflects the widespread adoption and longevity of these systems, particularly in server and embedded contexts where patching cycles were protracted. The recurring weakness classes cluster around injection vulnerabilities—OS command injection, code injection, SQL injection, and path traversal—alongside unclassified placeholder entries, patterns typical of systems with complex service architectures and legacy application interfaces. A notable tendency toward public exploit availability distinguishes this vendor's disclosures, reflecting the appeal of these systems to security researchers and attackers targeting production Unix infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
82
Total CVEs
More Total CVEs than 99% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Caldera over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 8, 1996
29 years ago
Most Recent CVE
May 8, 2014
4,461 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (82 CVEs).

82 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2000-0917HIGH
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
Dec 19, 200010.084NOYES
CVE-1999-0368HIGH
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
CVE-1999-0002HIGH
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
Oct 12, 199810.056NOYES
CVE-1999-0043CRITICAL
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Dec 4, 19969.855NONO
CVE-1999-0009HIGH
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Apr 8, 199810.054NOYES
CVE-2000-0844HIGH
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES
CVE-2000-0491HIGH
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY
May 24, 200010.044NOYES
CVE-1999-0042HIGH
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Apr 7, 199710.044NOYES
CVE-2002-0679HIGH
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREA
Sep 5, 200210.042NONO
CVE-1999-0879HIGH
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
Oct 1, 199910.039NOYES
View all 82 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products82 CVEs
9%
21%
70%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (1.2%)
Unknown81 (98.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.2%)
High0 (0.0%)
Unknown81 (98.8%)
User Interaction
None1 (1.2%)
Unknown81 (98.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (1.2%)
Unknown81 (98.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (82 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
23 CVEs
28.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Caldera.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Caldera — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Caldera's Products

View all 2 CNAs →

Top CWEs