VendorsMandrakeSoftmandrake_linuxall versions
Vulnerabilities

MandrakeSoft Mandrake Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

149CVEs
CVE-2005-0003
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
Published 2005-01-20 · Modified
2.1EPSS 0.005
CVE-2004-0535
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
Published 2004-06-08 · Modified
2.1EPSS 0.005
CVE-2004-0977
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Published 2004-10-20 · Modified
2.1EPSS 0.005
CVE-2004-1171
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.
Published 2004-12-10 · Modified
2.1EPSS 0.005
CVE-2004-0565
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
Published 2004-07-08 · Modified
2.1EPSS 0.004
CVE-2001-0416
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.
Published 2002-03-09 · Modified
2.1EPSS 0.004
CVE-2004-0975
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
Published 2004-10-20 · Modified
2.1EPSS 0.004
CVE-2004-0587
Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.
Published 2004-06-23 · Modified
2.1EPSS 0.004
CVE-2004-0974
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Published 2004-10-20 · Modified
2.1EPSS 0.004
CVE-2000-0633
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
Published 2000-10-13 · Modified
2.1EPSS 0.004
CVE-2000-0184
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.
Published 2000-04-25 · Modified
2.1EPSS 0.004
CVE-2004-0559
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
Published 2004-09-24 · Modified
2.1EPSS 0.004
CVE-2001-0178
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
Published 2001-05-07 · Modified
2.1EPSS 0.004
CVE-2004-2394
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
Published 2005-08-17 · Modified
2.1EPSS 0.004
CVE-2004-2395
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.
Published 2005-08-17 · Modified
2.1EPSS 0.003
CVE-2001-0474
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.
Published 2001-09-18 · Modified
2.1EPSS 0.003
CVE-2003-0462
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
Published 2003-07-25 · Modified
1.21 PoCEPSS 0.006
CVE-2001-0117
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
Published 2001-05-07 · Modified
1.2EPSS 0.004
CVE-2001-0139
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0142
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0125
exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0116
gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0118
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0119
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0120
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0138
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2001-0140
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
Published 2001-05-07 · Modified
1.2EPSS 0.003
CVE-2002-2001
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
Published 2005-07-14 · Modified
1.2EPSS 0.003
CVE-2000-0718
A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.
Published 2000-10-13 · Modified
1.2EPSS 0.003
← Prev4 / 4