← Vulnerability feed

Vulnerability record · CVE-2000-0306 · published 12 March 2001

CVE-2000-0306: Sco openserver vulnerability

SSco · Openserver

Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.

10.0 CVSS 2.0 High EPSS 3.7% · top 10.7%
10.0CVSS 2.0 base score
3.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2001-0797System V login buffer overflow via excessive argumentsThe login program on multiple System V based operating systems contains a buffer overflow that is triggered when a large number of arguments is passe…EPSS 95%analysed10.0CVE-1999-0835Ibm aix vulnerabilityDenial of service in BIND named via malformed SIG records.EPSS 1.5%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%10.0CVE-1999-0798Bsdi bsd os vulnerabilityBuffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.EPSS 1.6%10.0CVE-1999-1138Sco open desktop vulnerabilitySCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user…EPSS 1.6%9.8CVE-2003-0791Mozilla deserialization of untrusted data vulnerabilityThe Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as …EPSS 2.1%7.5CVE-2006-0072Sco openserver vulnerabilityBuffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument. NOTE: this i…EPSS 4.9%

Source: NIST National Vulnerability Database (record CVE-2000-0306), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.