cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 2 of 67
CVE-2006-1516P3MEDIUMCVSS 5.0PoCv4.0.0v4.0.1+48 more2006-05-05
CVE-2006-1516 [MEDIUM] CVE-2006-1516: The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5 The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.
nvd
CVE-2004-0835P3HIGHCVSS 7.5PoCfixed in 3.23.59≥ 4.0.0, < 4.0.192004-11-03
CVE-2004-0835 [HIGH] CVE-2004-0835: MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CR MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
nvd
CVE-2016-6663P3HIGHCVSS 7.0PoC≥ 5.5.0, ≤ 5.5.52≥ 5.6.0, ≤ 5.6.33+2 more2016-12-13
CVE-2016-6663 [HIGH] CWE-362 CVE-2016-6663: Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x befo Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x
nvd
CVE-2016-6664P3HIGHCVSS 7.0PoC≥ 5.5.0, ≤ 5.5.51≥ 5.6.0, ≤ 5.6.32+1 more2016-12-13
CVE-2016-6664 [HIGH] CWE-59 CVE-2016-6664: mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access
nvd
CVE-2013-1861P3MEDIUMCVSS 5.0PoC≥ 5.1.0, ≤ 5.1.69≥ 5.5.0, ≤ 5.5.31+1 more2013-03-28
CVE-2013-1861 [MEDIUM] CWE-119 CVE-2013-1861: MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing
nvd
CVE-2012-5615P3MEDIUMCVSS 5.0PoCv5.5.192012-12-03
CVE-2012-5615 [MEDIUM] CWE-200 CVE-2012-5615: Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, an Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.
nvd
CVE-2016-0639P3CRITICALCVSS 9.8≥ 5.6.0, ≤ 5.6.29≥ 5.7.0, ≤ 5.7.112016-04-21
CVE-2016-0639 [CRITICAL] CVE-2016-0639: Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote at Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Pluggable Authentication.
nvd
CVE-2015-4870P3MEDIUMCVSS 4.0PoC≥ 5.5.0, ≤ 5.5.45≥ 5.6.0, ≤ 5.6.262015-10-21
CVE-2015-4870 [MEDIUM] CVE-2015-4870: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
nvd
CVE-2005-0709P3MEDIUMCVSS 4.6PoCv3.23.49v4.0.0+25 more2005-05-02
CVE-2005-0709 [MEDIUM] CWE-94 CVE-2005-0709: MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
nvd
CVE-2016-0705P3CRITICALCVSS 9.8≥ 5.6.0, ≤ 5.6.29≥ 5.7.0, ≤ 5.7.112016-03-03
CVE-2016-0705 [CRITICAL] CVE-2016-0705: Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.
nvd
CVE-2022-21279P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21279 [MEDIUM] CVE-2022-21279: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21489P3MEDIUMCVSS 6.3≥ 7.4.00, ≤ 7.4.35≥ 7.5.00, ≤ 7.5.25+2 more2022-04-19
CVE-2022-21489 [MEDIUM] CVE-2022-21489: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2022-21280P3MEDIUMCVSS 6.3≥ 7.4.0, ≤ 7.4.34≥ 7.5.0, ≤ 7.5.24+2 more2022-01-19
CVE-2022-21280 [MEDIUM] CVE-2022-21280: Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the My
nvd
CVE-2016-2105P3HIGHCVSS 7.5≥ 5.6.0, ≤ 5.6.30≥ 5.7.0, ≤ 5.7.122016-05-05
CVE-2016-2105 [HIGH] CWE-190 CVE-2016-2105: Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t an Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
nvd
CVE-2005-0710P4MEDIUMCVSS 4.6PoCv3.23.49v4.0.0+25 more2005-05-02
CVE-2005-0710 [MEDIUM] CVE-2005-0710: MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
nvd
CVE-2019-14540P3CRITICALCVSS 9.8≥ 5.7.0, ≤ 5.7.30≥ 8.0.0, ≤ 8.0.202019-09-15
CVE-2019-14540 [CRITICAL] CWE-502 CVE-2019-14540: A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
nvd
CVE-2001-1274P4HIGHCVSS 7.5PoC≤ 3.23.312001-01-23
CVE-2001-1274 [HIGH] CVE-2001-1274: Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly g Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
nvd
CVE-2012-5627P4MEDIUMCVSS 4.0PoC≥ 5.5.0, < 5.5.292013-10-01
CVE-2012-5627 [MEDIUM] CWE-522 CVE-2012-5627: Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
nvd
CVE-2015-0411P3HIGHCVSS 7.5≥ 5.5.0, ≤ 5.5.40≥ 5.6.0, ≤ 5.6.212015-01-21
CVE-2015-0411 [HIGH] CVE-2015-0411: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
nvd
CVE-2020-11656P3CRITICALCVSS 9.8≥ 8.0.0, ≤ 8.0.222020-04-09
CVE-2020-11656 [CRITICAL] CWE-416 CVE-2020-11656: In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
nvd
Oracle MySQL vulnerabilities | cvebase