Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 1 of 67
CVE-2016-6662P1CRITICALCVSS 9.8ExploitedPoC≥ 5.5.0, ≤ 5.5.52≥ 5.6.0, ≤ 5.6.33+1 more2016-09-20
CVE-2016-6662 [CRITICAL] CWE-264 CVE-2016-6662: Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51,
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting genera
nvd
CVE-2022-21589P2MEDIUMCVSS 4.3Exploited≥ 5.7.0, ≤ 5.7.39≥ 8.0, ≤ 8.0.162022-10-18
CVE-2022-21589 [MEDIUM] CVE-2022-21589: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.39 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2017-3599P2HIGHCVSS 7.5PoC≥ 5.6.0, ≤ 5.6.35≥ 5.7.0, ≤ 5.7.172017-04-24
CVE-2017-3599 [HIGH] CWE-190 CVE-2017-3599: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2008-0226P2HIGHCVSS 7.5PoCv5.0.23v5.0.25+45 more2008-01-10
CVE-2008-0226 [HIGH] CWE-119 CVE-2008-0226: Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products,
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
nvd
CVE-2012-2122P2MEDIUMCVSS 5.1PoCv5.1.51v5.1.52+25 more2012-06-26
CVE-2012-2122 [MEDIUM] CWE-287 CVE-2012-2122: sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly auth
nvd
CVE-2009-4484P2HIGHCVSS 7.5PoC≥ 5.0.0, < 5.0.90≥ 5.1.0, < 5.1.43+1 more2009-12-30
CVE-2009-4484 [HIGH] CWE-787 CVE-2009-4484: Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCryp
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daem
nvd
CVE-2003-0780P3CRITICALCVSS 9.0PoCv3.23v3.23.2+59 more2003-09-22
CVE-2003-0780 [CRITICAL] CVE-2003-0780: Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x,
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
nvd
CVE-2003-0150P3CRITICALCVSS 9.0PoCv3.23.52v3.23.53+4 more2003-03-24
CVE-2003-0150 [CRITICAL] CVE-2003-0150: MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileg
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
nvd
CVE-2020-5398P2HIGHCVSS 7.5≥ 4.0.0, ≤ 4.0.12≥ 8.0.0, ≤ 8.0.202020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2012-5611P3MEDIUMCVSS 6.5PoCv5.1.53v5.5.192012-12-03
CVE-2012-5611 [MEDIUM] CWE-119 CVE-2012-5611: Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions throug
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FI
nvd
CVE-2006-1518P3MEDIUMCVSS 6.5PoCv5.0.0v5.0.3+10 more2006-05-05
CVE-2006-1518 [MEDIUM] CVE-2006-1518: Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow re
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.
nvd
CVE-2002-1375P3HIGHCVSS 7.5PoCv3.22.26v3.22.27+45 more2002-12-23
CVE-2002-1375 [HIGH] CVE-2002-1375: The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers t
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
nvd
CVE-2012-5612P3MEDIUMCVSS 6.5PoC≥ 5.5.0, ≤ 5.5.282012-12-03
CVE-2012-5612 [MEDIUM] CWE-787 CVE-2012-5612: Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5
Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (
nvd
CVE-2009-5026P3MEDIUMCVSS 6.8PoCv5.0.23v5.0.41+58 more2012-08-17
CVE-2009-5026 [MEDIUM] CWE-89 CVE-2009-5026: The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.
nvd
CVE-2012-5613P3MEDIUMCVSS 6.0PoCv5.5.192012-12-03
CVE-2012-5613 [MEDIUM] CWE-16 CVE-2012-5613: MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when conf
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this i
nvd
CVE-2002-1374P3HIGHCVSS 7.5PoCv3.22.26v3.22.27+45 more2002-12-23
CVE-2002-1374 [HIGH] CVE-2002-1374: The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attacke
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
nvd
CVE-2009-2446P3HIGHCVSS 8.5PoCv4.0.0v4.0.1+77 more2009-07-13
CVE-2009-2446 [HIGH] CWE-134 CVE-2009-2446: Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request
nvd
CVE-2002-1809P3HIGHCVSS 7.5PoCv3.23.2v3.23.3+32 more2002-12-31
CVE-2002-1809 [HIGH] CVE-2002-1809: The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL r
The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database.
nvd
CVE-2020-1967P3HIGHCVSS 7.5≤ 5.6.48≥ 5.7.0, ≤ 5.7.30+1 more2020-04-21
CVE-2020-1967 [HIGH] CWE-476 CVE-2020-1967: Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 han
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by
nvd
CVE-2006-4227P3MEDIUMCVSS 6.5PoCv5.0.0v5.1.6+2 more2006-08-18
CVE-2006-4227 [MEDIUM] CWE-20 CVE-2006-4227: MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security conte
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
nvd
1 / 67Next →