Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mandriva

First CVE: Oct 12, 2005Active for: 21 yearsTotal CVEs: 8

Mandriva's vulnerability profile centers on a range of Linux distributions and enterprise server platforms, including corporate and business server editions and network firewall appliances, which serve as foundational infrastructure for varied deployment environments. The vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the recurring weakness classes reflect common system-level exposure patterns including resource-access violations, input-validation gaps, symlink-following conditions, and memory-management flaws characteristic of native infrastructure software. Current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mandriva over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 12, 2005
20 years ago
Most Recent CVE
Nov 7, 2019
2,451 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-4854HIGH
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.
Jul 29, 20137.835NONO
CVE-2011-2162HIGH
Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (a
May 20, 201110.031NONO
CVE-2007-3915CRITICAL
Mondo 2.24 has insecure handling of temporary files.
Nov 7, 20199.129NONO
CVE-2010-2529MEDIUM
Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafte
Jul 28, 20105.020NONO
CVE-2009-0912HIGH
perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, w
Mar 16, 20097.218NONO
CVE-2009-0032MEDIUM
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink
Jan 27, 20096.918NONO
CVE-2007-3741MEDIUM
The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted im
Aug 27, 20074.315NONO
CVE-2005-3181LOW
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which preven
Oct 12, 20052.111NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
38%
38%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (12.5%)
Unknown7 (87.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High0 (0.0%)
Unknown7 (87.5%)
User Interaction
None1 (12.5%)
Unknown7 (87.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (12.5%)
Unknown7 (87.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mandriva.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mandriva — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mandriva's Products

View all 2 CNAs →

Top CWEs