
CVE-2006-0072 – SCO OpenServer 5.0.7 - 'termsh' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2006-0072
04 Jan 2006 — Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument. NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector. • https://www.exploit-db.com/exploits/1402 •

CVE-2005-2926
https://notcve.org/view.php?id=CVE-2005-2926
25 Oct 2005 — Stack-based buffer overflow in (1) backupsh and (2) authsh in SCO Openserver 5.0.7 allows local users to execute arbitrary code via a long HOME environment variable. • ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.40/SCOSA-2005.40.txt •

CVE-2003-1021
https://notcve.org/view.php?id=CVE-2003-1021
26 Jan 2005 — The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline. • ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.5/SCOSA-2005.5.txt •

CVE-2001-1508
https://notcve.org/view.php?id=CVE-2001-1508
31 Dec 2001 — Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument. • ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/CSSA-2001-SCO.38.txt •

CVE-2001-0797 – System V Derived /bin/login - Extraneous Arguments Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0797
12 Dec 2001 — Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin. Desbordamiento de búfer en la entrada a varios sistemas operativos basados en System V, permite a atacantes remotos la ejecución de comandos arbitrarios mediante un gran número de argumentos a través de servicios como telnet y rlogin. • https://www.exploit-db.com/exploits/16928 •

CVE-2001-1062
https://notcve.org/view.php?id=CVE-2001-1062
31 Aug 2001 — Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code. • ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.12/CSSA-2001-SCO.12.txt •

CVE-2001-0627
https://notcve.org/view.php?id=CVE-2001-0627
22 Aug 2001 — vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack. • ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.17/CSSA-2001-SCO.17.txt •

CVE-2001-0576 – SCO Open Server 5.0.6 - lpusers Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0576
27 Jul 2001 — lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter. • https://www.exploit-db.com/exploits/20739 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2001-0577 – SCO Open Server 5.0.6 - recon Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0577
27 Jul 2001 — recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument. • https://www.exploit-db.com/exploits/20742 •

CVE-2001-0578 – SCO Open Server 5.0.6 - lpforms Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0578
27 Jul 2001 — Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command. • https://www.exploit-db.com/exploits/20736 •