📦

mandrake_linux_corporate_server

Vendor: mandrakesoft

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 1 Remote Access
Total CVEs 9 Total Indexed
Avg. EPSS 1.11% Exploit Prob.
Latest CVE CVE-2007-6284 Jan 12

Security Vulnerability Index

Page 1 / 1
5.0 CVSS

The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.

EPSS: 5.10%
5.0 CVSS

nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote attackers to cause a denial of service (crond and other application crash) if they can cause an LDAP server to become unavailable. NOTE: it is not clear whether this attack scenario is sufficient to include this item in CVE.

EPSS: 0.74%
5.0 CVSS

libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.

EPSS: 0.96%
2.1 CVSS

Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.

EPSS: 0.05%
5.0 CVSS

Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).

EPSS: 0.95%
7.5 CVSS

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

EPSS: 1.78%
7.2 CVSS
CVE-2001-0279
Exploit Found

Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

EPSS: 0.22%
2.1 CVSS
CVE-2001-0169
Exploit Found

When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

EPSS: 0.14%
2.1 CVSS

kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.

EPSS: 0.10%