Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sco

First CVE: May 24, 1993Active for: 33 yearsTotal CVEs: 129
45.9
VTI Score
High

SCO's vulnerability footprint spans a modest but historically prominent lineup of Unix-derived operating systems and related infrastructure products, including OpenServer, UnixWare, and Open Desktop, which have maintained significant installed bases despite the vendor's limited ongoing development. While the disclosed vulnerabilities cluster across a broad range of weakness classes—many categorized as insufficient information or placeholder designations in historical disclosures—a meaningful subset recurs around input validation, path traversal, and memory-buffer boundary issues characteristic of native system software. The vendor's exposure concentrates in legacy and embedded Unix systems that often remain in production long after mainstream support, where they may occupy critical infrastructure roles with restricted update cycles. Public exploit code has been developed for a notable share of the vendor's disclosures, elevating the risk profile for unpatched or legacy deployments that remain internet-accessible or network-integrated. Defenders should prioritize inventory of systems running these products and assess network exposure; live severity, exploitation activity, and current CVE details are shown alongside this summary.

FAUCET AI Generated
129
Total CVEs
More Total CVEs than 99% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sco over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 1993
33 years ago
Most Recent CVE
Mar 16, 2011
5,609 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (129 CVEs).

129 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-0797HIGH
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as
Dec 12, 200110.088NOYES
CVE-1999-0128MEDIUM
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Dec 18, 19965.063NOYES
CVE-1999-0368HIGH
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
CVE-1999-0009HIGH
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Apr 8, 199810.054NOYES
CVE-2000-0306HIGH
Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.
Mar 12, 200110.036NOYES
CVE-2000-0026HIGH
Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.
Dec 21, 199910.036NOYES
CVE-2004-0390HIGH
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X
Dec 31, 20047.535NOYES
CVE-1999-0836HIGH
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
Dec 2, 199810.035NOYES
CVE-2004-0510HIGH
Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execma
Dec 23, 20047.233NOYES
CVE-2003-0282LOW
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result i
Jun 16, 20032.633NOYES
View all 129 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products129 CVEs
12%
36%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.6%)
Network2 (1.6%)
Unknown124 (96.1%)
Physical0 (0.0%)
Adjacent Network1 (0.8%)
Attack Complexity
Low4 (3.1%)
High1 (0.8%)
Unknown124 (96.1%)
User Interaction
None5 (3.9%)
Unknown124 (96.1%)
Required0 (0.0%)
Privileges Required
Low1 (0.8%)
High0 (0.0%)
None4 (3.1%)
Unknown124 (96.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (129 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
43 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sco.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sco — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sco's Products

View all 2 CNAs →

Top CWEs