Data General's vulnerability profile centers on legacy systems and infrastructure products, particularly its DG/UX operating system, which despite a narrow product scope retains presence in specialized deployments. The recurring weakness classes—classic buffer overflows and resource-exhaustion issues—reflect the memory-safety constraints of older systems, and public exploit code has frequently been developed for these disclosures. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Data General over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0009HIGH Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | Apr 8, 1998 | 10.0 | 54 | NO | YES |
CVE-1999-0038HIGH Buffer overflow in xlock program allows local users to execute commands as root. | Apr 26, 1997 | 8.4 | 32 | NO | YES |
CVE-1999-0152HIGH The DG/UX finger daemon allows remote command execution through shell metacharacters. | Aug 11, 1997 | 7.5 | 20 | NO | NO |
CVE-1999-0011MEDIUM Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. | Apr 8, 1998 | 5.4 | 19 | NO | NO |
CVE-1999-0019MEDIUM Delete or create a file via rpc.statd, due to invalid information. | Apr 24, 1996 | 5.0 | 17 | NO | NO |
CVE-1999-0010MEDIUM Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. | Apr 8, 1998 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Data General.
Media articles that mention a CVE ID that affects a product developed by Data General — matched by CVE ID, not by vendor name.