VYPR

Mandrake Linux

by Mandrakesoft

CVEs (135)

  • CVE-2004-1235Apr 14, 2005
    risk 0.03cvss epss 0.03

    Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

  • CVE-2004-0497Dec 6, 2004
    risk 0.03cvss epss 0.01

    Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.

  • CVE-2003-0462Aug 27, 2003
    risk 0.03cvss epss 0.01

    A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).

  • CVE-2002-1814Dec 31, 2002
    risk 0.03cvss epss 0.01

    Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.

  • CVE-2002-0004Feb 27, 2002
    risk 0.03cvss epss 0.01

    Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.

  • CVE-2002-0002Jan 31, 2002
    risk 0.03cvss epss 0.05

    Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.

  • CVE-2001-0736Oct 18, 2001
    risk 0.03cvss epss 0.01

    Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

  • CVE-2001-0440Jul 2, 2001
    risk 0.03cvss epss 0.05

    Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.

  • CVE-2001-0279May 3, 2001
    risk 0.03cvss epss 0.01

    Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.

  • CVE-2001-0169Mar 26, 2001
    risk 0.03cvss epss 0.01

    When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

  • CVE-2000-1134Jan 9, 2001
    risk 0.03cvss epss 0.01

    Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

  • CVE-2000-1095Jan 9, 2001
    risk 0.03cvss epss 0.01

    modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.

  • CVE-2000-0607Jun 21, 2000
    risk 0.03cvss epss 0.01

    Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.

  • CVE-2000-0454May 29, 2000
    risk 0.03cvss epss 0.01

    Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.

  • CVE-1999-1008May 17, 2000
    risk 0.03cvss epss 0.01

    xsoldier program allows local users to gain root access via a long argument.

  • CVE-2000-0336Apr 21, 2000
    risk 0.03cvss epss 0.01

    Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

  • CVE-2000-0052Jan 4, 2000
    risk 0.03cvss epss 0.01

    Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.

  • CVE-1999-1477Sep 23, 1999
    risk 0.03cvss epss 0.01

    Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.

  • CVE-2007-0454Feb 6, 2007
    risk 0.01cvss epss 0.06

    Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

  • CVE-2004-0803Dec 23, 2004
    risk 0.01cvss epss 0.08

    Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.

Page 2 of 7