📦

mandrake_linux

Vendor: mandrakesoft

Actively Exploited 0 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 2 Remote Access
Total CVEs 42 Total Indexed
Avg. EPSS 1.15% Exploit Prob.
Latest CVE CVE-2007-6284 Jan 12

Security Vulnerability Index

Page 2 / 5
7.2 CVSS

Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.

EPSS: 0.05%
10.0 CVSS

time server daemon timed allows remote attackers to cause a denial of service via malformed packets.

EPSS: 0.99%
4.6 CVSS

kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.

EPSS: 0.07%
7.2 CVSS

Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.

EPSS: 0.06%
7.5 CVSS

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

EPSS: 1.78%
7.2 CVSS
CVE-2001-0279
Exploit Found

Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

EPSS: 0.22%
2.1 CVSS
CVE-2001-0169
Exploit Found

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

EPSS: 0.14%
2.1 CVSS

kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.

EPSS: 0.10%
7.2 CVSS

The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.

EPSS: 0.05%
10.0 CVSS

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

EPSS: 0.46%