← Back

Mandrakesoft

mandrakesoft

139 CVEs • 7 products

Products (7)

Click to collapse
Toggle

CVEs (139)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Caldera
ConectivaMandrakesoft+1 more
5Linux
Mandrake LinuxMandrake Linux Corporate Server+2 more
Apr 16, 2026
Mar 26, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
4Mandrakesoft
RedhatTrustix+1 more
5Linux
Mandrake LinuxMandrake Linux Corporate Server+2 more
Apr 16, 2026
Mar 26, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary...Show more
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.Show less
5Immunix
MandrakesoftNational Science Foundation+2 more
5Immunix
LinuxMandrake Linux+2 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
3Immunix
MandrakesoftRedhat
3Immunix
LinuxMandrake Linux
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
5Caldera
DebianImmunix+2 more
7Debian Linux
ImmunixLinux+4 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
4Debian
ImmunixMandrakesoft+1 more
5Debian Linux
ImmunixLinux+2 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
4Conectiva
DebianMandrakesoft+1 more
4Debian Linux
LinuxMandrake Linux+1 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.
6Conectiva
DebianFreebsd+3 more
7Debian Linux
FreebsdLinux+4 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
3Debian
ExmhMandrakesoft
4Debian Linux
ExmhMandrake Linux+1 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
3Immunix
MandrakesoftRedhat
3Immunix
LinuxMandrake Linux
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.
3Immunix
MandrakesoftRedhat
3Immunix
LinuxMandrake Linux
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.
3Immunix
MandrakesoftRedhat
3Immunix
LinuxMandrake Linux
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
4Immunix
MandrakesoftRedhat+1 more
5Immunix
LinuxMandrake Linux+2 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
3Immunix
MandrakesoftRedhat
3Immunix
LinuxMandrake Linux
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
2Mandrakesoft
Php
2Mandrake Linux
Php
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that...Show more
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.Show less
2Mandrakesoft
Php
2Mandrake Linux
Php
Apr 16, 2026
Jan 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP script...Show more
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.Show less
7Caldera
ConectivaHp+4 more
9Hp Ux
ImmunixLinux+6 more
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to over...Show more
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.Show less
5Conectiva
ImmunixMandrakesoft+2 more
5Immunix
LinuxLinux+2 more
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
1Mandrakesoft
1Mandrake Linux
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and ga...Show more
The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.Show less
1Mandrakesoft
1Mandrake Linux
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.