Unixware

Vendor:

First CVE: Apr 18, 1996 · Active for 30 years

66
Total CVEs
More Total CVEs than 99% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Unixware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 1996
30 years ago
Most Recent CVE
May 6, 2009
6,291 days ago

CVE Severity & Scoring

Unixware66 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local1 (1.5%)
Network0 (0.0%)
Unknown64 (97.0%)
Physical0 (0.0%)
Adjacent Network1 (1.5%)
Attack Complexity
Low1 (1.5%)
High1 (1.5%)
Unknown64 (97.0%)
User Interaction
None2 (3.0%)
Unknown64 (97.0%)
Required0 (0.0%)
Privileges Required
Low1 (1.5%)
High0 (0.0%)
None1 (1.5%)
Unknown64 (97.0%)

Top CVEs

Signals from CVEs in this product scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Feb 9, 199910.060NOYES
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Apr 8, 199810.054NOYES
Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.
Dec 21, 199910.036NOYES
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
Dec 2, 199810.035NOYES
Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the
Dec 11, 20007.533NOYES
Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARC
Dec 1, 20037.230NOYES
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
Jul 24, 19967.229NOYES
A vulnerability in the Sendmail configuration file sendmail.cf as installed in SCO UnixWare 7.1.0 and earlier allows an attacker to gain root privileges.
Mar 12, 200110.028NONO
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. (dot dot) sequences that point to a directo
Mar 30, 20097.227NOYES
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH env
Mar 30, 20097.227NOYES

Exploit Exposure

Signals from CVEs in this product scope (66 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
25 CVEs
37.9% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (66 CVEs).

Media Mentions

Signals from CVEs in this product scope (66 CVEs).

Top CNAs Publishing CVEs For Unixware

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1.4_mp212.10.5%00
7.1.4145.91.2%06
7.1.3_up15.60.5%00
7.1.3_mp512.10.5%00
7.1.3135.20.8%04
7.1.214.60.5%00
7.1.1_m512.10.5%00
7.1.1617.20.8%01
7.1.1175.51.2%09
7.1.017.20.4%00
7.1156.01.1%010
7.0.1117.64.5%07
7.0.017.20.4%00
7.0207.15.4%012
746.11.0%01
3.2v417.20.6%00
2.1.017.20.4%00
2.196.35.2%03
2.0.x17.20.4%00
2.0.317.20.8%01