VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Mandrakesoft
>
Mandrake Linux
> 10.1
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2005-03-01
CVE-2004-1051
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
local
low complexity
mandrakesoft
todd-miller
debian
trustix
ubuntu
7.2
7.2
2005-03-01
CVE-2004-0983
Denial Of Service vulnerability in Yukihiro Matsumoto Ruby CGI Module
The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
network
low complexity
yukihiro-matsumoto
gentoo
mandrakesoft
ubuntu
5.0
5.0
2005-02-21
CVE-2005-0503
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
local
low complexity
uim
mandrakesoft
4.6
4.6
2005-02-09
CVE-2004-0975
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
local
low complexity
mandrakesoft
openssl
gentoo
2.1
2.1
2005-02-09
CVE-2004-0974
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
local
low complexity
netatalk
mandrakesoft
redhat
2.1
2.1
2005-02-09
CVE-2004-0937
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
network
low complexity
archive-zip
broadcom
ca
eset-software
kaspersky-lab
mcafee
rav-antivirus
sophos
gentoo
mandrakesoft
suse
7.5
7.5
2005-01-27
CVE-2004-0936
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
network
low complexity
archive-zip
broadcom
ca
eset-software
kaspersky-lab
mcafee
rav-antivirus
sophos
gentoo
mandrakesoft
suse
7.5
7.5
2005-01-27
CVE-2004-0935
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
network
low complexity
archive-zip
broadcom
ca
eset-software
kaspersky-lab
mcafee
rav-antivirus
sophos
gentoo
mandrakesoft
suse
7.5
7.5
2005-01-27
CVE-2004-0934
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
network
low complexity
archive-zip
broadcom
ca
eset-software
kaspersky-lab
mcafee
rav-antivirus
sophos
gentoo
mandrakesoft
suse
7.5
7.5
2005-01-27
CVE-2004-0933
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
network
low complexity
archive-zip
broadcom
ca
eset-software
kaspersky-lab
mcafee
rav-antivirus
sophos
gentoo
mandrakesoft
suse
7.5
7.5
«
Previous
1
2
(current)
3
4
»
Next