Openserver

Vendor:

First CVE: Sep 17, 1993 · Active for 32 years

72
Total CVEs
More Total CVEs than 99% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 1993
32 years ago
Most Recent CVE
Jan 4, 2006
7,506 days ago

CVE Severity & Scoring

Openserver72 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network2 (2.8%)
Unknown68 (94.4%)
Physical0 (0.0%)
Adjacent Network1 (1.4%)
Attack Complexity
Low3 (4.2%)
High1 (1.4%)
Unknown68 (94.4%)
User Interaction
None4 (5.6%)
Unknown68 (94.4%)
Required0 (0.0%)
Privileges Required
Low1 (1.4%)
High0 (0.0%)
None3 (4.2%)
Unknown68 (94.4%)

Top CVEs

Signals from CVEs in this product scope (72 CVEs).

72 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as
Dec 12, 200110.088NOYES
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Dec 18, 19965.063NOYES
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.
Mar 12, 200110.036NOYES
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X
Dec 31, 20047.535NOYES
Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execma
Dec 23, 20047.233NOYES
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
Jul 1, 19975.032NOYES
Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument. NOTE: this is probably a different vulnera
Jan 4, 20067.530NOYES
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaSc
Oct 7, 20039.830NONO
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t
Nov 23, 20047.529NONO

Exploit Exposure

Signals from CVEs in this product scope (72 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
26.4% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (72 CVEs).

Media Mentions

Signals from CVEs in this product scope (72 CVEs).

Top CNAs Publishing CVEs For Openserver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.036.73.2%00
5.0.7216.12.9%05
5.0.6a75.514.2%04
5.0.6245.76.0%07
5.0.5156.39.7%04
5.0.497.315.6%03
5.0.357.226.9%03
5.0.2126.718.0%05
5.0.146.523.6%02
5.0.017.20.4%00
5.0236.211.1%09
555.20.9%00
3.067.30.9%01
2.017.20.8%01