Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mandrakesoft

First CVE: Dec 19, 1994Active for: 32 yearsTotal CVEs: 151
49.1
VTI Score
High

Mandrakesoft's vulnerability footprint centers on a focused set of Linux distributions and network security appliances, including Mandrake Linux, corporate server variants, and firewall products, that served a defined market segment despite modest product breadth. The recurring exposure spans memory-safety issues such as buffer-boundary violations, input-validation weaknesses, OS command injection, and authorization flaws that are characteristic of system software and network infrastructure written in lower-level languages. Public exploit code has frequently become available for this vendor's vulnerabilities, reflecting the appeal of its products as targets for automation and weaponization. Defenders managing legacy Mandrakesoft systems should treat publicly disclosed vulnerabilities as high-priority due to the availability of exploit tooling; live severity, exploitation, and remediation guidance are shown alongside this summary.

FAUCET AI Generated
151
Total CVEs
More Total CVEs than 99% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mandrakesoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 1994
31 years ago
Most Recent CVE
Feb 29, 2008
6,720 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (151 CVEs).

151 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0932HIGH
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
CVE-2003-0434HIGH
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Jul 24, 20037.557NOYES
CVE-2004-0386HIGH
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
May 4, 200410.049NOYES
CVE-2004-0460HIGH
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p
Aug 6, 200410.048NONO
CVE-2002-0083CRITICAL
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Mar 15, 20029.848NOYES
CVE-2001-0136MEDIUM
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly ins
Mar 12, 20015.045NOYES
CVE-2000-0844HIGH
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES
CVE-2004-1096HIGH
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both lo
Jan 10, 20057.543NOYES
CVE-2004-0934HIGH
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compres
Jan 27, 20057.542NOYES
CVE-2004-0935HIGH
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whic
Jan 27, 20057.542NOYES
View all 151 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products151 CVEs
23%
29%
47%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.7%)
Network1 (0.7%)
Unknown149 (98.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (1.3%)
High0 (0.0%)
Unknown149 (98.7%)
User Interaction
None2 (1.3%)
Unknown149 (98.7%)
Required0 (0.0%)
Privileges Required
Low1 (0.7%)
High0 (0.0%)
None1 (0.7%)
Unknown149 (98.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (151 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
38 CVEs
25.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mandrakesoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mandrakesoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mandrakesoft's Products

View all 2 CNAs →

Top CWEs