Orange Business Services
Vigil@nce Vigil@nce Vigil@nce
we track for your security since 1999
  home presentation vulnerabilities documentation contact  
subscriber area subscriber area
free access free access
The Vigil@nce team watches vulnerabilities impacting your computers, and then offers solutions, a database and tools to correct them.
recent vulnerabilities recent vulnerabilities
tracked products tracked products
RSS feed RSS feed
vulnerable product
Vulnerabilities of Mandriva Linux

Mandriva Linux vulnerability: Cross Site Scripting of modules
An attacker can trigger several Cross Site Scripting in the mod_info, mod_status, mod_imagemap, mod_ldap and mod_proxy_ftp modules, in order to execute JavaScript code in the context of the web site.

Mandriva Linux vulnerability: information disclosure in CBC mode, Lucky 13
An attacker can inject wrongly encrypted messages in a TLS/DTLS session in mode CBC, and measure the delay before the error message reception, in order to progressively guess the clear content of the session.

Mandriva Linux vulnerability: vulnerabilities of SWAT
An attacker can use two vulnerabilities of Samba Web Administration Tool, in order to trigger a Clickjacking or a Cross Site Request Forgery.

Mandriva Linux vulnerability: database corruption via a public key
An attacker can create a malformed public key, and can invite a GnuPG user to import it, in order to stop the application, or to corrupt the keyring database.

Mandriva Linux vulnerability: denial of service via address conversion
An attacker who can query a named server which supports address conversion from IPv4 to IPv6, can send a query of type AAAA which makes the server halt.

Display other vulnerabilities of Mandriva Linux described by Vigil@nce...




















Copyright 1999-2013 Vigil@nce. Vigil@nce is a service from Orange Business Services. Site map. Legal notice. Version française