Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-1420NULL Pointer Dereference in Mysql

Severity
2.1LOWNVD
EPSS
0.1%
top 76.11%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 12
Latest updateMay 1

Description

MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

NVDmysql/mysql5.0.33+13
NVDoracle/mysql4 versions+3

Patches

🔴Vulnerability Details

1
GHSA
GHSA-gf4h-r5mj-gf9j: MySQL 52022-05-01

💥Exploits & PoCs

1
Exploit-DB
MySQL 5.0.x - Single Row SubSelect Remote Denial of Service2007-03-09

📋Vendor Advisories

2
Ubuntu
MySQL vulnerability2007-03-22
Red Hat
Single MySQL worker can be crashed (NULL deref) with certain SELECT statements2007-03-09

💬Community

2
Bugzilla
CVE-2007-1420 Single MySQL worker can be crashed (NULL deref) with certain SELECT statements2007-03-16
Bugzilla
CVE-2007-1420 Single MySQL worker can be crashed (NULL deref) with certain SELECT statements2007-03-16
CVE-2007-1420 — NULL Pointer Dereference in Mysql | cvebase