Oracle MySQL vulnerabilities

1,328 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,328
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH71MEDIUM1064LOW181

Vulnerabilities

Page 24 of 67
CVE-2020-14623MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14623 [MEDIUM] CVE-2020-14623: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2020-14654MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14654 [MEDIUM] CVE-2020-14654: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-14634LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14634 [LOW] CVE-2020-14634: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a sub
nvd
CVE-2020-14633LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14633 [LOW] CVE-2020-14633: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or de
nvd
CVE-2020-15358MEDIUMCVSS 5.5≤ 8.0.222020-06-27
CVE-2020-15358 [MEDIUM] CWE-787 CVE-2020-15358: In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectO In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
nvd
CVE-2020-11080HIGHCVSS 7.5≥ 7.3.0, ≤ 7.3.30≥ 7.4.0, ≤ 7.4.29+3 more2020-06-03
CVE-2020-11080 [HIGH] CWE-707 CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of se In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vul
nvd
CVE-2020-1967HIGHCVSS 7.5≤ 5.6.48≥ 5.7.0, ≤ 5.7.30+1 more2020-04-21
CVE-2020-1967 [HIGH] CWE-476 CVE-2020-1967: Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 han Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by
nvd
CVE-2020-2814MEDIUMCVSS 4.9≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.28+1 more2020-04-15
CVE-2020-2814 [MEDIUM] CVE-2020-2814: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.47 and prior, 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd
CVE-2020-2812MEDIUMCVSS 4.9≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2020-04-15
CVE-2020-2812 [MEDIUM] CVE-2020-2812: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Sup Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vul
nvd
CVE-2020-2923MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.192020-04-15
CVE-2020-2923 [MEDIUM] CVE-2020-2923: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2020-2928MEDIUMCVSS 4.9≥ 8.0.0, < 8.0.192020-04-15
CVE-2020-2928 [MEDIUM] CVE-2020-2928: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2020-2930MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.192020-04-15
CVE-2020-2930 [MEDIUM] CVE-2020-2930: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2020-2853MEDIUMCVSS 4.9≥ 8.0.0, < 8.0.192020-04-15
CVE-2020-2853 [MEDIUM] CVE-2020-2853: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2020-2804MEDIUMCVSS 5.9≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2020-04-15
CVE-2020-2804 [MEDIUM] CVE-2020-2804: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2020-2893MEDIUMCVSS 4.9≥ 8.0.0, < 8.0.192020-04-15
CVE-2020-2893 [MEDIUM] CVE-2020-2893: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2020-2780MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2020-04-15
CVE-2020-2780 [MEDIUM] CVE-2020-2780: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2020-2921MEDIUMCVSS 4.4≥ 8.0.0, < 8.0.192020-04-15
CVE-2020-2921 [MEDIUM] CVE-2020-2921: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2020-2896MEDIUMCVSS 4.9≥ 8.0.0, < 8.0.192020-04-15
CVE-2020-2896 [MEDIUM] CVE-2020-2896: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2020-2926MEDIUMCVSS 4.4≥ 8.0.0, < 8.0.192020-04-15
CVE-2020-2926 [MEDIUM] CVE-2020-2926: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS) Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2020-2761MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.182020-04-15
CVE-2020-2761 [MEDIUM] CVE-2020-2761: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
Oracle MySQL vulnerabilities | cvebase