Debian Mariadb-10.5 vulnerabilities
80 known vulnerabilities affecting debian/mariadb-10.5.
Total CVEs
80
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH40MEDIUM37LOW2
Vulnerabilities
Page 2 of 4
CVE-2022-32087HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-32087 [HIGH] CVE-2022-32087: mariadb-10.5 - MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27457HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27457 [HIGH] CVE-2022-27457: mariadb-10.5 - MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-32086HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-32086 [HIGH] CVE-2022-32086: mariadb-10.5 - MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the co...
MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27451HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27451 [HIGH] CVE-2022-27451: mariadb-10.5 - MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27379HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27379 [HIGH] CVE-2022-27379: mariadb-10.5 - An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v...
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-24052HIGHCVSS 7.8fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2022
CVE-2022-24052 [HIGH] CVE-2022-24052: mariadb-10.5 - MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation V...
MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper val
debian
CVE-2022-27383HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27383 [HIGH] CVE-2022-27383: mariadb-10.5 - MariaDB Server v10.6 and below was discovered to contain an use-after-free in th...
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27377HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27377 [HIGH] CVE-2022-27377: mariadb-10.5 - MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27447HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27447 [HIGH] CVE-2022-27447: mariadb-10.5 - MariaDB Server v10.9 and below was discovered to contain a use-after-free via th...
MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27376HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27376 [HIGH] CVE-2022-27376: mariadb-10.5 - MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in ...
MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-32085HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-32085 [HIGH] CVE-2022-32085: mariadb-10.5 - MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27445HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27445 [HIGH] CVE-2022-27445: mariadb-10.5 - MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-24048HIGHCVSS 7.8fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2022
CVE-2022-24048 [HIGH] CVE-2022-24048: mariadb-10.5 - MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation ...
MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper va
debian
CVE-2022-27381HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27381 [HIGH] CVE-2022-27381: mariadb-10.5 - An issue in the component Field::set_default of MariaDB Server v10.6 and below w...
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-32089HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-32089 [HIGH] CVE-2022-32089: mariadb-10.5 - MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the co...
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27452HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27452 [HIGH] CVE-2022-27452: mariadb-10.5 - MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27446HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27446 [HIGH] CVE-2022-27446: mariadb-10.5 - MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-32088HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-32088 [HIGH] CVE-2022-32088: mariadb-10.5 - MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27444HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27444 [HIGH] CVE-2022-27444: mariadb-10.5 - MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian
CVE-2022-27456HIGHCVSS 7.5fixed in mariadb-10.5 1:10.5.18-0+deb11u1 (bullseye)2022
CVE-2022-27456 [HIGH] CVE-2022-27456: mariadb-10.5 - MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
Scope: local
bullseye: resolved (fixed in 1:10.5.18-0+deb11u1)
debian