CVE-2014-0433
published 2014-01-15CVE-2014-0433: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote attackers to affect availability via unknown vectors…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.51%
83.0th percentile
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote attackers to affect availability via unknown vectors related to Thread Pooling.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql | <= 5.6.13 | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: unspecified vulnerability related to Thread Pooling DoS (CPU Jan 2014)
vendor_redhat·2014-01-14·CVSS 4.3
CVE-2014-0433 [MEDIUM] mysql: unspecified vulnerability related to Thread Pooling DoS (CPU Jan 2014)
mysql: unspecified vulnerability related to Thread Pooling DoS (CPU Jan 2014)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote attackers to affect availability via unknown vectors related to Thread Pooling.
Statement: Not Vulnerable. This issue does not affect the version of mysql55-mysql package as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of mysql as shipped with Red Hat Enterprise Linux 6.
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: mariadb55-mariadb (Red Hat Software Collections) - Not affected
Package: mysql55-mysql (Red Hat Software Co
GHSA
GHSA-29wf-p89m-vpvf: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-17
CVE-2014-0433 [MEDIUM] GHSA-29wf-p89m-vpvf: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote attackers to affect availability via unknown vectors related to Thread Pooling.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6638 Kernel: net: tcp: potential DoS via SYN+FIN messages
bugzilla·2014-02-17·CVSS 7.8
CVE-2012-6638 [HIGH] CVE-2012-6638 Kernel: net: tcp: potential DoS via SYN+FIN messages
CVE-2012-6638 Kernel: net: tcp: potential DoS via SYN+FIN messages
Linux kernel built with the TCP/IP networking support(CONFIG_INET) is
vulnerable to a possible DoS attack. It could occur when accepting new TCP
connection requests with 'SYN+FIN' flags instead of only 'SYN' flag set.
A remote user/program could use this flaw to cause DoS by sending multiple
connection requests to a machine.
Upstream fix:
-> https://git.kernel.org/linus/fdf5af0daf8019cec2396cdef8fb042d80fe71fa
Discussion:
Statement:
This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0433 https://rhn.redhat.com/errata/RHSA-2014-0433.html
---
Bugzilla
CVE-2014-0433 mysql: unspecified vulnerability related to Thread Pooling DoS (CPU Jan 2014)
bugzilla·2014-01-15·CVSS 4.3
CVE-2014-0433 [MEDIUM] CVE-2014-0433 mysql: unspecified vulnerability related to Thread Pooling DoS (CPU Jan 2014)
CVE-2014-0433 mysql: unspecified vulnerability related to Thread Pooling DoS (CPU Jan 2014)
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-0433 to
the following vulnerability:
Name: CVE-2014-0433
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0433
Assigned: 20131212
Reference: http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.6.13 and earlier allows remote attackers to affect
availability via unknown vectors related to Thread Pooling.
Discussion:
Upstream data suggests that this issue only affects the version of MySQL 5.6.13 and earlier.
This issue does not affect the version of mysql as shipped with Red Hat Enterprise Linux 5 and 6.
This issue does no
http://secunia.com/advisories/56491http://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64895https://exchange.xforce.ibmcloud.com/vulnerabilities/90375http://secunia.com/advisories/56491http://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64895https://exchange.xforce.ibmcloud.com/vulnerabilities/90375
2014-01-15
Published