CVE-2020-2752
published 2020-04-15CVE-2020-2752: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and…
PriorityP426medium5.3CVSS 3.1
AVNACHPRLUINSUCNINAH
EPSS
2.32%
81.7th percentile
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mariadb | mariadb | >= 0 < 10.3.23-r0 | 10.3.23-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.4.13-r0 | 10.4.13-r0 |
| mariadb | mariadb | >= 0 < 10.2.32-r0 | 10.2.32-r0 |
| mariadb | mariadb | >= 0 < 10.3.23-r0 | 10.3.23-r0 |
| mariadb | mariadb | >= 10.1.0 < 10.1.45 | 10.1.45 |
| mariadb | mariadb | >= 10.2.0 < 10.2.32 | 10.2.32 |
| mariadb | mariadb | >= 10.3.0 < 10.3.23 | 10.3.23 |
| mariadb | mariadb | >= 10.4.0 < 10.4.13 | 10.4.13 |
| mariadb | mariadb | >= 5.5.0 < 5.5.68 | 5.5.68 |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
Ubuntu
MariaDB vulnerabilities
vendor_ubuntu·2020-10-27·CVSS 8.8
CVE-2020-2760 [HIGH] MariaDB vulnerabilities
Title: MariaDB vulnerabilities
Summary: Several security issues were fixed in MariaDB.
It was discovered that MariaDB didn't properly validate the content of a packet
received from a server. A remote attacker could use this vulnerability to sent
a specialy crafted file to cause a denial of service. (CVE-2020-13249)
It was discovered that MariaDB has other security issues. An attacker can cause
a hang or frequently repeatable crash (denial of service). (CVE-2020-15180,
CVE-2020-2752, CVE-2020-2760, CVE-2020-2812, CVE-2020-2814)
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart
Oracle
Oracle Oracle MySQL Risk Matrix: C API — CVE-2020-2752
vendor_oracle·2020-04-15·CVSS 5.3
CVE-2020-2752 [MEDIUM] Oracle Oracle MySQL Risk Matrix: C API — CVE-2020-2752
Oracle Oracle MySQL Risk Matrix: C API vulnerability
CVE: CVE-2020-2752
CVSS: 5.3
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Red Hat
mysql: C API unspecified vulnerability (CPU Apr 2020)
vendor_redhat·2020-04-14·CVSS 5.3
CVE-2020-2752 [MEDIUM] mysql: C API unspecified vulnerability (CPU Apr 2020)
mysql: C API unspecified vulnerability (CPU Apr 2020)
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Out of support scope
Package: mysql (Red Hat Enterprise Linux 6) - Out of support scope
Package: mariadb-galera
GHSA
GHSA-vcxq-55mq-gj87: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API)
ghsa_unreviewed·2022-05-24
CVE-2020-2752 [LOW] GHSA-vcxq-55mq-gj87: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API)
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
OSV
mariadb-10.1, mariadb-10.3 vulnerabilities
osv·2020-10-27·CVSS 8.8
CVE-2020-13249 [HIGH] mariadb-10.1, mariadb-10.3 vulnerabilities
mariadb-10.1, mariadb-10.3 vulnerabilities
It was discovered that MariaDB didn't properly validate the content of a packet
received from a server. A remote attacker could use this vulnerability to sent
a specialy crafted file to cause a denial of service. (CVE-2020-13249)
It was discovered that MariaDB has other security issues. An attacker can cause
a hang or frequently repeatable crash (denial of service). (CVE-2020-15180,
CVE-2020-2752, CVE-2020-2760, CVE-2020-2812, CVE-2020-2814)
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
OSV
CVE-2020-2752: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API)
osv·2020-04-15·CVSS 5.3
CVE-2020-2752 [MEDIUM] CVE-2020-2752: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API)
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2752 mariadb-connector-c: mysql: C API unspecified vulnerability (CPU Apr 2020) [fedora-all]
bugzilla·2020-05-27·CVSS 5.3
CVE-2020-2752 [MEDIUM] CVE-2020-2752 mariadb-connector-c: mysql: C API unspecified vulnerability (CPU Apr 2020) [fedora-all]
CVE-2020-2752 mariadb-connector-c: mysql: C API unspecified vulnerability (CPU Apr 2020) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2020-2752 mysql: C API unspecified vulnerability (CPU Apr 2020)
bugzilla·2020-05-14·CVSS 5.3
CVE-2020-2752 [MEDIUM] CVE-2020-2752 mysql: C API unspecified vulnerability (CPU Apr 2020)
CVE-2020-2752 mysql: C API unspecified vulnerability (CPU Apr 2020)
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client.
External References:
https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixMSQL
Discussion:
According to upstream advisory, this issue was fixed in MySQL versions 5.7.28 and 8.0.18, which were released at the time of Oct 2019 CPU. Only 5.6 branch was
Bugzilla
CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb: various flaws [fedora-all]
bugzilla·2020-04-30·CVSS 5.3
CVE-2020-2752 [MEDIUM] CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb: various flaws [fedora-all]
CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.3/mariadb: various flaws [fedora-all]
bugzilla·2020-04-30·CVSS 5.3
CVE-2020-2752 [MEDIUM] CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.3/mariadb: various flaws [fedora-all]
CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.3/mariadb: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.4/mariadb: various flaws [fedora-all]
bugzilla·2020-04-30·CVSS 5.3
CVE-2020-2752 [MEDIUM] CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.4/mariadb: various flaws [fedora-all]
CVE-2020-2752 CVE-2020-2760 CVE-2020-2812 CVE-2020-2814 mariadb:10.4/mariadb: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00054.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UW2ED32VEUHXFN2J3YQE27JIBV4SC2PI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4X2BMF3EILMTXGOZDTPYS3KT5VWLA2P/https://security.gentoo.org/glsa/202012-08https://security.gentoo.org/glsa/202105-27https://security.netapp.com/advisory/ntap-20200416-0003/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00054.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UW2ED32VEUHXFN2J3YQE27JIBV4SC2PI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4X2BMF3EILMTXGOZDTPYS3KT5VWLA2P/https://security.gentoo.org/glsa/202012-08https://security.gentoo.org/glsa/202105-27https://security.netapp.com/advisory/ntap-20200416-0003/https://www.oracle.com/security-alerts/cpuapr2020.html
2020-04-15
Published