Vulnerabilities (CVE)

Vendor filter

Mandrakesoft Subscribe

Product filter

Mandrake Multi Network Firewall Subscribe

Filter

17 total CVE
CVE Vendors Products Updated CVSS
CVE-2003-0367 5 Turbolinux, Openpkg, Mandrakesoft and 2 more 9 Mandrake Multi Network Firewall, Turbolinux Advanced Server, Mandrake Linux Corporate Server and 6 more 2019-05-23 2.1
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2004-0496 5 Gentoo, Suse, Mandrakesoft and 2 more 13 Mandrake Multi Network Firewall, Linux Kernel, Suse Email Server and 10 more 2018-10-30 7.2
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
CVE-2007-1352 8 Turbolinux, Ubuntu, X.org and 5 more 12 Mandrake Multi Network Firewall, Linux Advanced Workstation, Enterprise Linux Desktop and 9 more 2018-10-16 3.8
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
CVE-2007-1351 7 Ubuntu, X.org, Rpath and 4 more 9 Mandrake Multi Network Firewall, Linux Advanced Workstation, Enterprise Linux Desktop and 6 more 2018-10-16 8.5
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
CVE-2007-5116 4 Larry Wall, Mandrakesoft, Openpkg and 1 more 4 Openpkg, Mandrake Multi Network Firewall, Enterprise Linux and 1 more 2018-10-15 7.5
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
CVE-2005-0003 4 Avaya, Mandrakesoft, Linux and 1 more 15 Mandrake Multi Network Firewall, Linux Kernel, Converged Communications Server and 12 more 2017-10-11 2.1
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute...
CVE-2004-1235 7 Linux, Ubuntu, Conectiva and 4 more 20 Mandrake Multi Network Firewall, Linux Kernel, Converged Communications Server and 17 more 2017-10-11 6.2
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
CVE-2004-0975 3 Gentoo, Openssl, Mandrakesoft 5 Mandrake Linux Corporate Server, Mandrake Linux, Mandrake Multi Network Firewall and 2 more 2017-10-11 2.1
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
CVE-2004-0565 4 Gentoo, Trustix, Linux and 1 more 6 Mandrake Multi Network Firewall, Linux Kernel, Linux and 3 more 2017-10-11 2.1
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
CVE-2004-0535 6 Linux, Conectiva, Suse and 3 more 17 Mandrake Multi Network Firewall, Linux Kernel, Suse Office Server and 14 more 2017-10-11 2.1
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by...
CVE-2004-0497 7 Linux, Conectiva, Redhat and 4 more 9 Mandrake Multi Network Firewall, Linux Kernel, Linux and 6 more 2017-10-11 2.1
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
CVE-2004-0488 8 Tinysofa, Mod Ssl, Sgi and 5 more 10 Propack, Mandrake Multi Network Firewall, Linux and 7 more 2017-10-11 7.5
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long...
CVE-2003-0462 2 Mandrakesoft, Linux 4 Mandrake Multi Network Firewall, Linux Kernel, Mandrake Linux and 1 more 2017-10-11 1.2
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
CVE-2004-2395 1 Mandrakesoft 3 Mandrake Linux, Mandrake Multi Network Firewall, Mandrake Linux Corporate Server 2017-07-11 2.1
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.
CVE-2004-2394 1 Mandrakesoft 3 Mandrake Linux, Mandrake Multi Network Firewall, Mandrake Linux Corporate Server 2017-07-11 2.1
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
CVE-2004-1051 5 Todd Miller, Mandrakesoft, Trustix and 2 more 7 Mandrake Multi Network Firewall, Debian Linux, Mandrake Linux Corporate Server and 4 more 2017-07-11 7.2
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
CVE-2004-0834 3 Gentoo, Mandrakesoft, Speedtouch 5 Mandrake Linux Corporate Server, Mandrake Linux, Mandrake Multi Network Firewall and 2 more 2017-07-11 7.2
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.