cbcvebase.
CVE-2004-0836
published 2004-11-03

CVE-2004-0836: Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service…

PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
9.80%
95.0th percentile
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).

Affected

3 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
oraclemysql>= 3.20 < 3.23.493.23.49
oraclemysql>= 4.0.0 < 4.0.214.0.21

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.