SCO's vulnerability footprint spans a modest but historically prominent lineup of Unix-derived operating systems and related infrastructure products, including OpenServer, UnixWare, and Open Desktop, which have maintained significant installed bases despite the vendor's limited ongoing development. While the disclosed vulnerabilities cluster across a broad range of weakness classes—many categorized as insufficient information or placeholder designations in historical disclosures—a meaningful subset recurs around input validation, path traversal, and memory-buffer boundary issues characteristic of native system software. The vendor's exposure concentrates in legacy and embedded Unix systems that often remain in production long after mainstream support, where they may occupy critical infrastructure roles with restricted update cycles. Public exploit code has been developed for a notable share of the vendor's disclosures, elevating the risk profile for unpatched or legacy deployments that remain internet-accessible or network-integrated. Defenders should prioritize inventory of systems running these products and assess network exposure; live severity, exploitation activity, and current CVE details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sco over time
Signals from CVEs in this vendor scope (129 CVEs).
129 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0797HIGH Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as | Dec 12, 2001 | 10.0 | 88 | NO | YES |
CVE-1999-0128MEDIUM Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | Dec 18, 1996 | 5.0 | 63 | NO | YES |
CVE-1999-0368HIGH Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | Feb 9, 1999 | 10.0 | 60 | NO | YES |
CVE-1999-0009HIGH Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | Apr 8, 1998 | 10.0 | 54 | NO | YES |
CVE-2000-0306HIGH Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message. | Mar 12, 2001 | 10.0 | 36 | NO | YES |
CVE-2000-0026HIGH Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. | Dec 21, 1999 | 10.0 | 36 | NO | YES |
CVE-2004-0390HIGH SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X | Dec 31, 2004 | 7.5 | 35 | NO | YES |
CVE-1999-0836HIGH UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack. | Dec 2, 1998 | 10.0 | 35 | NO | YES |
CVE-2004-0510HIGH Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execma | Dec 23, 2004 | 7.2 | 33 | NO | YES |
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result i | Jun 16, 2003 | 2.6 | 33 | NO | YES |
Signals from CVEs in this vendor scope (129 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sco.
Media articles that mention a CVE ID that affects a product developed by Sco — matched by CVE ID, not by vendor name.