← Vulnerability feed

Vulnerability record · CVE-2005-0351 · published 7 April 2005

CVE-2005-0351: Sco openserver memory buffer overflow vulnerability

SSco · Openserver

Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.

4.6 CVSS 2.0 Medium EPSS 0.40% · top 68.1% CWE-119 · Memory buffer overflow
4.6CVSS 2.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0351 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2001-0797System V login buffer overflow via excessive argumentsThe login program on multiple System V based operating systems contains a buffer overflow that is triggered when a large number of arguments is passe…EPSS 95%analysed10.0CVE-2000-0306Sco openserver vulnerabilityBuffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.EPSS 3.7%10.0CVE-1999-0835Ibm aix vulnerabilityDenial of service in BIND named via malformed SIG records.EPSS 1.5%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%10.0CVE-1999-0798Bsdi bsd os vulnerabilityBuffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.EPSS 1.6%10.0CVE-1999-1138Sco open desktop vulnerabilitySCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user…EPSS 1.6%9.8CVE-2003-0791Mozilla deserialization of untrusted data vulnerabilityThe Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as …EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2005-0351), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.