peter bassill · operator
$ cve CVE-2004-0390 JSON

CVE-2004-0390 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.58% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
scoopenserver

Public exploits

SourceTitleDate
exploit-dbSCO OpenServer 5.0.x - StartX Weak XHost Permissions2001-05-07

References

→ the Explorer  ·  watch your stack  ·  NVD