Mandrake Linux

Vendor:

First CVE: Dec 19, 1994 · Active for 31 years

134
Total CVEs
More Total CVEs than 99% of tracked products
11.2
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mandrake Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 1994
31 years ago
Most Recent CVE
Feb 29, 2008
6,724 days ago

CVE Severity & Scoring

Mandrake Linux134 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local1 (0.7%)
Network1 (0.7%)
Unknown132 (98.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (1.5%)
High0 (0.0%)
Unknown132 (98.5%)
User Interaction
None2 (1.5%)
Unknown132 (98.5%)
Required0 (0.0%)
Privileges Required
Low1 (0.7%)
High0 (0.0%)
None1 (0.7%)
Unknown132 (98.5%)

Top CVEs

Signals from CVEs in this product scope (134 CVEs).

134 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
Jul 24, 20037.557NOYES
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
May 4, 200410.049NOYES
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p
Aug 6, 200410.048NONO
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Mar 15, 20029.848NOYES
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly ins
Mar 12, 20015.045NOYES
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both lo
Jan 10, 20057.543NOYES
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compres
Jan 27, 20057.542NOYES
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whic
Jan 27, 20057.542NOYES

Exploit Exposure

Signals from CVEs in this product scope (134 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
36 CVEs
26.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (134 CVEs).

Media Mentions

Signals from CVEs in this product scope (134 CVEs).

Top CNAs Publishing CVEs For Mandrake Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
cs3.012.10.6%00
cs2.112.10.6%00
9.2365.14.6%04
9.1135.28.3%02
9.0106.211.7%03
8.294.81.9%01
8.1106.63.5%03
8.0116.54.2%04
7.317.57.8%00
7.2334.53.2%08
7.1405.12.2%010
7.0334.81.7%09
6.1294.41.4%07
6.0223.81.1%05
2008.024.81.5%00
2007.124.81.5%00
2007.0_x86_6414.60.4%00
200744.83.2%01
200656.93.4%01
10.256.55.5%01