Debian Mariadb-10.5 vulnerabilities

80 known vulnerabilities affecting debian/mariadb-10.5.

Total CVEs
80
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH40MEDIUM37LOW2

Vulnerabilities

Page 4 of 4
CVE-2021-46662MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-46662 [MEDIUM] CVE-2021-46662: mariadb-10.5 - MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of... MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery. Scope: local bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
debian
CVE-2021-46666MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.11-1 (bullseye)2021
CVE-2021-46666 [MEDIUM] CVE-2021-46666: mariadb-10.5 - MariaDB before 10.6.2 allows an application crash because of mishandling of a pu... MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause. Scope: local bullseye: resolved (fixed in 1:10.5.11-1)
debian
CVE-2021-2154MEDIUMCVSS 4.9fixed in mariadb-10.5 1:10.5.10-1 (bullseye)2021
CVE-2021-2154 [MEDIUM] CVE-2021-2154: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DM... Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
debian
CVE-2021-46668MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-46668 [MEDIUM] CVE-2021-46668: mariadb-10.5 - MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTI... MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures. Scope: local bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
debian
CVE-2021-46665MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-46665 [MEDIUM] CVE-2021-46665: mariadb-10.5 - MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorr... MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations. Scope: local bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
debian
CVE-2021-2194MEDIUMCVSS 4.9fixed in mariadb-10.5 1:10.5.8-1 (bullseye)2021
CVE-2021-2194 [MEDIUM] CVE-2021-2194: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). S... Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
debian
CVE-2021-46667MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-46667 [MEDIUM] CVE-2021-46667: mariadb-10.5 - MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an applicati... MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. Scope: local bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
debian
CVE-2021-35604MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-35604 [MEDIUM] CVE-2021-35604: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). S... Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
debian
CVE-2021-46657MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.11-1 (bullseye)2021
CVE-2021-46657 [MEDIUM] CVE-2021-46657: mariadb-10.5 - get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certa... get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY. Scope: local bullseye: resolved (fixed in 1:10.5.11-1)
debian
CVE-2021-46664MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-46664 [MEDIUM] CVE-2021-46664: mariadb-10.5 - MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr f... MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr. Scope: local bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
debian
CVE-2021-46659MEDIUMCVSS 5.5fixed in mariadb-10.5 1:10.5.15-0+deb11u1 (bullseye)2021
CVE-2021-46659 [MEDIUM] CVE-2021-46659: mariadb-10.5 - MariaDB before 10.7.2 allows an application crash because it does not recognize ... MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW. Scope: local bullseye: resolved (fixed in 1:10.5.15-0+deb11u1)
debian
CVE-2021-2372MEDIUMCVSS 4.4fixed in mariadb-10.5 1:10.5.12-0+deb11u1 (bullseye)2021
CVE-2021-2372 [MEDIUM] CVE-2021-2372: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). S... Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
debian
CVE-2021-2389MEDIUMCVSS 5.9fixed in mariadb-10.5 1:10.5.12-0+deb11u1 (bullseye)2021
CVE-2021-2389 [MEDIUM] CVE-2021-2389: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). S... Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
debian
CVE-2021-2166MEDIUMCVSS 4.9fixed in mariadb-10.5 1:10.5.10-1 (bullseye)2021
CVE-2021-2166 [MEDIUM] CVE-2021-2166: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DM... Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
debian
CVE-2020-15180CRITICALCVSS 9.0fixed in mariadb-10.5 1:10.5.6-1 (bullseye)2020
CVE-2020-15180 [CRITICAL] CVE-2020-15180: mariadb-10.5 - A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitiza... A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47,
debian
CVE-2020-14765MEDIUMCVSS 6.5fixed in mariadb-10.5 1:10.5.8-1 (bullseye)2020
CVE-2020-14765 [MEDIUM] CVE-2020-14765: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FT... Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
debian
CVE-2020-14789MEDIUMCVSS 4.9fixed in mariadb-10.5 1:10.5.8-1 (bullseye)2020
CVE-2020-14789 [MEDIUM] CVE-2020-14789: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FT... Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
debian
CVE-2020-14812MEDIUMCVSS 4.9fixed in mariadb-10.5 1:10.5.8-1 (bullseye)2020
CVE-2020-14812 [MEDIUM] CVE-2020-14812: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Lo... Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
debian
CVE-2020-14776MEDIUMCVSS 4.9fixed in mariadb-10.5 1:10.5.8-1 (bullseye)2020
CVE-2020-14776 [MEDIUM] CVE-2020-14776: mariadb-10.5 - Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). S... Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
debian
CVE-2020-28912LOWCVSS 6.42020
CVE-2020-28912 [MEDIUM] CVE-2020-28912: mariadb-10.5 - With MariaDB running on Windows, when local clients connect to the server over n... With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL c
debian
Debian Mariadb-10.5 vulnerabilities | cvebase