Vulnerability Details CVE-1999-1138
                SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.005
                        
                    
                    
                        
                            EPSS Ranking 66.7%
                        
                    
                 
                
                    CVSS Severity
                    
                    
                        
                            CVSS v2 Score 10.0
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-1999-1138
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:sco:open_desktop:1.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:sco:open_desktop:2.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:sco:open_desktop:3.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:sco:open_desktop_lite:3.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:sco:openserver:3.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                        Sco
                                        »
                                        
Unix
                                        » 
Version: system_v386_3.2_operating_system
                                    
 
                                    
                                        
                                            cpe:2.3:o:sco:unix:system_v386_3.2_operating_system
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                        Sco
                                        »
                                        
Unix
                                        » 
Version: system_v386_3.2_operating_system_2.0
                                    
 
                                    
                                        
                                            cpe:2.3:o:sco:unix:system_v386_3.2_operating_system_2.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                        Sco
                                        »
                                        
Unix
                                        » 
Version: system_v386_3.2_operating_system_4.0
                                    
 
                                    
                                        
                                            cpe:2.3:o:sco:unix:system_v386_3.2_operating_system_4.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                        Sco
                                        »
                                        
Unix
                                        » 
Version: system_v386_3.2_operating_system_4.x
                                    
 
                                    
                                        
                                            cpe:2.3:o:sco:unix:system_v386_3.2_operating_system_4.x