CVE-2004-0390 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.58% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sco | openserver |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SCO OpenServer 5.0.x - StartX Weak XHost Permissions | 2001-05-07 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html
- http://www.securityfocus.com/advisories/6684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16113
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0424.html
- http://www.securityfocus.com/advisories/6684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16113
→ the Explorer · watch your stack · NVD