Mandrakesoft's vulnerability footprint centers on a focused set of Linux distributions and network security appliances, including Mandrake Linux, corporate server variants, and firewall products, that served a defined market segment despite modest product breadth. The recurring exposure spans memory-safety issues such as buffer-boundary violations, input-validation weaknesses, OS command injection, and authorization flaws that are characteristic of system software and network infrastructure written in lower-level languages. Public exploit code has frequently become available for this vendor's vulnerabilities, reflecting the appeal of its products as targets for automation and weaponization. Defenders managing legacy Mandrakesoft systems should treat publicly disclosed vulnerabilities as high-priority due to the availability of exploit tooling; live severity, exploitation, and remediation guidance are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mandrakesoft over time
Signals from CVEs in this vendor scope (151 CVEs).
151 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0932HIGH McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via | Jan 27, 2005 | 7.5 | 71 | NO | YES |
CVE-2003-0434HIGH Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. | Jul 24, 2003 | 7.5 | 57 | NO | YES |
CVE-2004-0386HIGH Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header. | May 4, 2004 | 10.0 | 49 | NO | YES |
CVE-2004-0460HIGH Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p | Aug 6, 2004 | 10.0 | 48 | NO | NO |
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2001-0136MEDIUM Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly ins | Mar 12, 2001 | 5.0 | 45 | NO | YES |
CVE-2000-0844HIGH Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun | Nov 14, 2000 | 10.0 | 44 | NO | YES |
CVE-2004-1096HIGH Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both lo | Jan 10, 2005 | 7.5 | 43 | NO | YES |
CVE-2004-0934HIGH Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compres | Jan 27, 2005 | 7.5 | 42 | NO | YES |
CVE-2004-0935HIGH Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whic | Jan 27, 2005 | 7.5 | 42 | NO | YES |
Signals from CVEs in this vendor scope (151 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mandrakesoft.
Media articles that mention a CVE ID that affects a product developed by Mandrakesoft — matched by CVE ID, not by vendor name.