CVE-2014-0412
published 2014-01-15CVE-2014-0412: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote…
PriorityP418medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
3.36%
87.5th percentile
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mariadb | mariadb | >= 10.0.0 < 10.0.8 | 10.0.8 |
| mariadb | mariadb | >= 5.5.0 < 5.5.35 | 5.5.35 |
| oracle | mysql | 5.1.0 – 5.1.72 | — |
| oracle | mysql | 5.5.0 – 5.5.34 | — |
| oracle | mysql | 5.6.0 – 5.6.14 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv3.4LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqg3-g5ff-hqrr: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2014-0412 [MEDIUM] GHSA-fqg3-g5ff-hqrr: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
OSV
openjdk-7 vulnerabilities
osv·2015-01-28·CVSS 3.4
CVE-2014-3566 openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive data over the network. (CVE-2014-6593)
A vulnerability was discovere
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2014-01-21
CVE-2013-5891 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,
Ubuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
Instructions: In general, a standard system update will make all the necessary c
Red Hat
mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)
vendor_redhat·2014-01-14·CVSS 4.0
CVE-2014-0412 [MEDIUM] mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)
mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2428 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
bugzilla·2014-04-15·CVSS 7.6
CVE-2014-2428 [HIGH] CVE-2014-2428 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
CVE-2014-2428 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-2428). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redh
Bugzilla
CVE-2014-0432 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (Libraries)
bugzilla·2014-04-15·CVSS 9.3
CVE-2014-0432 [CRITICAL] CVE-2014-0432 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (Libraries)
CVE-2014-0432 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (Libraries)
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the Libraries component (CVE-2014-0432). Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redhat.com/errata/
Bugzilla
CVE-2014-2409 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
bugzilla·2014-04-15·CVSS 6.4
CVE-2014-2409 [MEDIUM] CVE-2014-2409 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
CVE-2014-2409 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-2409). Upstream has CVSSv2 scored this issue as: 6.4/AV:N/AC:L/Au:N/C:P/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redh
Bugzilla
CVE-2014-2422 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (JavaFX)
bugzilla·2014-04-15·CVSS 6.8
CVE-2014-2422 [MEDIUM] CVE-2014-2422 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (JavaFX)
CVE-2014-2422 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (JavaFX)
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the JavaFX component (CVE-2014-2422). Upstream has CVSSv2 scored this issue as: 6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redhat.com/errata/RHSA-2
Bugzilla
CVE-2014-2420 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
bugzilla·2014-04-15·CVSS 2.6
CVE-2014-2420 [LOW] CVE-2014-2420 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
CVE-2014-2420 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-2420). Upstream has CVSSv2 scored this issue as: 2.6/AV:N/AC:H/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redh
Bugzilla
CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
bugzilla·2014-04-15·CVSS 5.0
CVE-2014-0449 [MEDIUM] CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
CVE-2014-0449 Oracle JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Oracle Java SE 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0449). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redh
Bugzilla
CVE-2014-0448 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (Deployment)
bugzilla·2014-04-15·CVSS 7.6
CVE-2014-0448 [HIGH] CVE-2014-0448 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (Deployment)
CVE-2014-0448 Oracle JDK: unspecified vulnerability fixed in 7u55 and 8u5 (Deployment)
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0448). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Oracle Java for Red Hat Enterprise Linux 6
Oracle Java for Red Hat Enterprise Linux 5
Via RHSA-2014:0413 https://rhn.redhat.com/errata/RHSA-2014-0413.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2014:0412 https://rhn.redhat.com/errat
Bugzilla
CVE-2014-0412 CVE-2014-0437 CVE-2013-5908 CVE-2014-0420 CVE-2014-0393 CVE-2013-5891 CVE-2014-0386 CVE-2014-0401 CVE-2014-0402 community-mysql: various flaws [fedora-all]
bugzilla·2014-01-16·CVSS 4.0
CVE-2014-0412 [MEDIUM] CVE-2014-0412 CVE-2014-0437 CVE-2013-5908 CVE-2014-0420 CVE-2014-0393 CVE-2013-5891 CVE-2014-0386 CVE-2014-0401 CVE-2014-0402 community-mysql: various flaws [fedora-all]
CVE-2014-0412 CVE-2014-0437 CVE-2013-5908 CVE-2014-0420 CVE-2014-0393 CVE-2013-5891 CVE-2014-0386 CVE-2014-0401 CVE-2014-0402 community-mysql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed
Bugzilla
CVE-2014-0412 CVE-2014-0437 CVE-2013-5908 CVE-2014-0420 CVE-2014-0393 CVE-2013-5891 CVE-2014-0386 CVE-2014-0401 CVE-2014-0402 mariadb: various flaws [fedora-all]
bugzilla·2014-01-16·CVSS 4.0
CVE-2014-0412 [MEDIUM] CVE-2014-0412 CVE-2014-0437 CVE-2013-5908 CVE-2014-0420 CVE-2014-0393 CVE-2013-5891 CVE-2014-0386 CVE-2014-0401 CVE-2014-0402 mariadb: various flaws [fedora-all]
CVE-2014-0412 CVE-2014-0437 CVE-2013-5908 CVE-2014-0420 CVE-2014-0393 CVE-2013-5891 CVE-2014-0386 CVE-2014-0401 CVE-2014-0402 mariadb: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the
Bugzilla
CVE-2014-0412 mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)
bugzilla·2014-01-15·CVSS 4.0
CVE-2014-0412 [MEDIUM] CVE-2014-0412 mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)
CVE-2014-0412 mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0412 to
the following vulnerability:
Name: CVE-2014-0412
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0412
Assigned: 20131212
Reference: http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier
allows remote authenticated users to affect availability via unknown
vectors related to InnoDB.
Discussion:
Created mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1054043]
---
Created community-mysql tracking bugs for this issue:
Affects: fedora-all [bug 105404
http://osvdb.org/102067http://rhn.redhat.com/errata/RHSA-2014-0164.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0173.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0186.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0189.htmlhttp://secunia.com/advisories/56491http://secunia.com/advisories/56541http://secunia.com/advisories/56580http://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://ubuntu.com/usn/usn-2086-1http://www.debian.org/security/2014/dsa-2845http://www.debian.org/security/2014/dsa-2848http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64880https://exchange.xforce.ibmcloud.com/vulnerabilities/90378http://osvdb.org/102067http://rhn.redhat.com/errata/RHSA-2014-0164.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0173.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0186.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0189.htmlhttp://secunia.com/advisories/56491http://secunia.com/advisories/56541http://secunia.com/advisories/56580http://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://ubuntu.com/usn/usn-2086-1http://www.debian.org/security/2014/dsa-2845http://www.debian.org/security/2014/dsa-2848http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64880https://exchange.xforce.ibmcloud.com/vulnerabilities/90378
2014-01-15
Published