Mandriva's vulnerability profile centers on a range of Linux distributions and enterprise server platforms, including corporate and business server editions and network firewall appliances, which serve as foundational infrastructure for varied deployment environments. The vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, while the recurring weakness classes reflect common system-level exposure patterns including resource-access violations, input-validation gaps, symlink-following conditions, and memory-management flaws characteristic of native infrastructure software. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mandriva over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4854HIGH The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9. | Jul 29, 2013 | 7.8 | 35 | NO | NO |
CVE-2011-2162HIGH Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (a | May 20, 2011 | 10.0 | 31 | NO | NO |
CVE-2007-3915CRITICAL Mondo 2.24 has insecure handling of temporary files. | Nov 7, 2019 | 9.1 | 29 | NO | NO |
CVE-2010-2529MEDIUM Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafte | Jul 28, 2010 | 5.0 | 20 | NO | NO |
CVE-2009-0912HIGH perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, w | Mar 16, 2009 | 7.2 | 18 | NO | NO |
CVE-2009-0032MEDIUM CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink | Jan 27, 2009 | 6.9 | 18 | NO | NO |
CVE-2007-3741MEDIUM The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted im | Aug 27, 2007 | 4.3 | 15 | NO | NO |
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which preven | Oct 12, 2005 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mandriva.
Media articles that mention a CVE ID that affects a product developed by Mandriva — matched by CVE ID, not by vendor name.