Vulnerabilities > Mandrakesoft > Mandrake Linux > 2007

DATE CVE VULNERABILITY TITLE RISK
2007-11-07 CVE-2007-5116 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
7.5
2007-09-18 CVE-2007-4938 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
7.6
2007-06-21 CVE-2007-2833 Remote Denial of Service vulnerability in GNU Emacs Image Processing
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
network
low complexity
debian mandrakesoft gnu
7.8
2007-04-06 CVE-2007-1352 Local Integer Overflow vulnerability in X.Org LibXFont
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
3.8
2007-04-06 CVE-2007-1351 Numeric Errors vulnerability in multiple products
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
8.5
2007-03-20 CVE-2007-1547 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
The ReadRequestFromClient function in server/os/io.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via multiple simultaneous connections, which triggers a NULL pointer dereference.
network
low complexity
mandrakesoft radscan
7.8
2007-03-20 CVE-2007-1546 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function in server/dia/auutil.c.
network
low complexity
mandrakesoft radscan
5.0
2007-03-20 CVE-2007-1545 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (server crash) via a nonexistent client ID.
network
low complexity
mandrakesoft radscan
5.0
2007-03-20 CVE-2007-1544 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value.
network
low complexity
mandrakesoft radscan
5.0
2007-03-20 CVE-2007-1543 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a long path slave name in a USL socket connection.
network
low complexity
mandrakesoft radscan
critical
10.0