Xinuos maintains a narrow portfolio centered on legacy Unix-based operating systems, primarily OpenServer and UnixWare, which serve specialized enterprise and embedded deployments. The observed vulnerability signal reflects application-layer input-handling weaknesses, particularly cross-site scripting and OS command injection, which are characteristic of older server codebases with extended operational lifespans. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xinuos over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0230MEDIUM TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by | Aug 18, 2004 | 5.0 | 74 | NO | YES |
CVE-2020-25494CRITICAL Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook. | Dec 18, 2020 | 9.8 | 62 | NO | YES |
CVE-2020-25495MEDIUM A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the p | Dec 18, 2020 | 6.1 | 41 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xinuos.
Media articles that mention a CVE ID that affects a product developed by Xinuos — matched by CVE ID, not by vendor name.