CVE-2014-0001Improper Restriction of Operations within the Bounds of a Memory Buffer in Mariadb

Severity
7.5HIGHNVD
EPSS
20.7%
top 4.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateMay 13

Description

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

Also affects: Enterprise Linux 5, 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7pq3-qq22-gpw3: Buffer overflow in client/mysql2022-05-13
OSV
CVE-2014-0001: Buffer overflow in client/mysql2014-01-31

💥Exploits & PoCs

1
Exploit-DB
Publish-It 3.6d - Buffer Overflow2014-02-06

📋Vendor Advisories

21
VMware
VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues2015-01-27
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26
Red Hat
webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-26

💬Community

22
Bugzilla
CVE-2014-1308 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1303 webkitgtk: heap-based buffer overflow (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1326 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1333 webkitgtk: arbitrary code execution and denial of service via a crafted web site (WSA-2015-0001)2015-01-27
Bugzilla
CVE-2014-1713 webkitgtk: use-after-free in the AttributeSetter function (WSA-2015-0001)2015-01-27