Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-4870Oracle Mysql vulnerability

11 documents9 sources
Severity
4.0MEDIUMNVD
EPSS
22.1%
top 4.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 21
Latest updateMay 13

Description

Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages9 packages

NVDoracle/mysql5.5.05.5.45+1
NVDoracle/solaris11.3
NVDmariadb/mariadb5.5.05.5.46+2

Also affects: Debian Linux 7.0, 8.0, Fedora 23, Ubuntu Linux 12.04, 14.04, 15.04, 15.10, Enterprise Linux 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4466-76rw-3vm6: Unspecified vulnerability in Oracle MySQL Server 52022-05-13
OSV
CVE-2015-4870: Unspecified vulnerability in Oracle MySQL Server 52015-10-21
CVEList
CVE-2015-4870: Unspecified vulnerability in Oracle MySQL Server 52015-10-21

💥Exploits & PoCs

1
Exploit-DB
MySQL 5.5.45 - procedure analyse Function Denial of Service2016-05-30

📋Vendor Advisories

3
Ubuntu
MySQL vulnerabilities2015-10-26
Red Hat
mysql: unspecified vulnerability related to Server:Parser (CPU October 2015)2015-10-21
Apache
Apache nifi: CVE-2018-1310

💬Community

3
Bugzilla
CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4816 CVE-2015-4819 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836 CVE-2015-4858 CVE-2015-4861 CVE-2015-4870 CVE-2015-4879 CVE-2015-4895 CVE-2015-10-29
Bugzilla
CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4816 CVE-2015-4819 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836 CVE-2015-4858 CVE-2015-4861 CVE-2015-4870 CVE-2015-4879 CVE-2015-4895 CVE-2015-10-29
Bugzilla
CVE-2015-4870 mysql: unspecified vulnerability related to Server:Parser (CPU October 2015)2015-10-23
CVE-2015-4870 — Oracle Mysql vulnerability | cvebase