Digital's vulnerability footprint centers on legacy operating systems and platforms including Unix, OSF/1, Ultrix, and OpenVMS variants that served foundational roles in enterprise and research computing but are no longer in widespread active use. The recurring weakness classes, dominated by buffer overflow conditions and related memory-safety issues, reflect the memory-management constraints of systems developed before modern exploit mitigations became standard. Despite the historical nature of this vendor's product line, vulnerabilities affecting these platforms have frequently acquired public exploit code, underscoring the enduring interest in legacy system compromises for research, archeological security assessment, and specialized environments where these systems remain operational. Defenders maintaining or studying these platforms should review available patches and mitigations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digital over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0046HIGH Buffer overflow of rlogin program using TERM environmental variable. | Feb 6, 1997 | 10.0 | 67 | NO | YES |
CVE-1999-0128MEDIUM Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | Dec 18, 1996 | 5.0 | 63 | NO | YES |
CVE-1999-0513MEDIUM ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. | Jan 5, 1998 | 5.0 | 60 | NO | YES |
CVE-1999-0170HIGH Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. | Jan 1, 1997 | 7.5 | 39 | NO | YES |
CVE-2001-0369HIGH Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name). | Jun 27, 2001 | 7.2 | 33 | NO | YES |
CVE-1999-0691HIGH Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name. | Sep 13, 1999 | 7.2 | 29 | NO | YES |
CVE-1999-0073HIGH Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access. | Oct 13, 1995 | 10.0 | 28 | NO | NO |
CVE-2002-1129HIGH Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument. | Oct 4, 2002 | 7.2 | 27 | NO | YES |
CVE-1999-1194HIGH chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges. | May 1, 1991 | 7.2 | 27 | NO | YES |
CVE-2001-0134HIGH Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execu | Mar 12, 2001 | 10.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digital.
Media articles that mention a CVE ID that affects a product developed by Digital — matched by CVE ID, not by vendor name.