cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 3 of 67
CVE-2019-2632P3HIGHCVSS 7.5≥ 5.7.0, ≤ 5.7.25≥ 8.0.0, ≤ 8.0.152019-04-23
CVE-2019-2632 [HIGH] CVE-2019-2632: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2010-3683P4MEDIUMCVSS 4.0PoCv5.1v5.1.1+50 more2011-01-11
CVE-2010-3683 [MEDIUM] CVE-2010-3683: Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE reque Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a crafted request.
nvd
CVE-2006-3081P4MEDIUMCVSS 4.0PoCv4.0.18v4.1.4+4 more2006-06-19
CVE-2006-3081 [MEDIUM] CVE-2006-3081: mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote autho mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
nvd
CVE-2016-9841P3CRITICALCVSS 9.8≥ 5.5.0, ≤ 5.5.61≥ 5.6.0, ≤ 5.6.41+2 more2017-05-23
CVE-2016-9841 [CRITICAL] CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by levera inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2006-3469P4MEDIUMCVSS 4.0PoCv4.1.6v4.1.7+13 more2006-07-21
CVE-2006-3469 [MEDIUM] CWE-134 CVE-2006-3469: Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
nvd
CVE-2000-0045P4MEDIUMCVSS 6.4PoCv3.22.27v3.22.29+1 more2000-01-11
CVE-2000-0045 [MEDIUM] CVE-2000-0045: MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
nvd
CVE-2010-1850P3MEDIUMCVSS 6.0v5.0.0v5.0.3+60 more2010-06-08
CVE-2010-1850 [MEDIUM] CWE-119 CVE-2010-1850: Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.
nvd
CVE-2012-5614P4MEDIUMCVSS 4.0PoC≥ 5.1.0, ≤ 5.1.67≥ 5.5.0, ≤ 5.5.292012-12-03
CVE-2012-5614 [MEDIUM] CVE-2012-5614: Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versi Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
nvd
CVE-2015-9244P3MEDIUM≥ 0, < 2.0.0-alpha82020-09-01
CVE-2015-9244 [MEDIUM] CWE-89 SQL Injection in mysql SQL Injection in mysql Versions of `mysql` prior to 2.0.0-alpha8 are affected by a SQL Injection vulnerability in the `mysql.escape()` function, which does not properly escape object keys. ## Recommendation Update to version 2.0.0-alpha8 or later.
ghsaosv
CVE-2024-21272P3HIGHCVSS 7.5v9.0.02024-10-15
CVE-2024-21272 [HIGH] CWE-306 CVE-2024-21272: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Suppor Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeove
nvd
CVE-2009-4019P4MEDIUMCVSS 4.0PoCv5.0.0v5.0.3+54 more2009-11-30
CVE-2009-4019 [MEDIUM] CVE-2009-4019: mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors duri mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) v
nvd
CVE-2010-2008P4LOWCVSS 3.5PoCfixed in 5.1.482010-07-13
CVE-2010-2008 [LOW] CWE-77 CVE-2010-2008: MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a deni MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain
nvd
CVE-2010-3682P4MEDIUMCVSS 4.0PoCv5.1.1v5.1.2+81 more2011-01-11
CVE-2010-3682 [MEDIUM] CVE-2010-3682: Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a de Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
nvd
CVE-2018-2696P3HIGHCVSS 7.5≥ 5.6.0, ≤ 5.6.38≥ 5.7.0, ≤ 5.7.202018-01-18
CVE-2018-2696 [HIGH] CVE-2018-2696: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privi Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2020-5258P3HIGHCVSS 7.5≥ 7.3.0, ≤ 7.3.29≥ 7.4.0, ≤ 7.4.28+3 more2020-03-10
CVE-2020-5258 [HIGH] CWE-94 CVE-2020-5258: In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the ba
nvd
CVE-2012-3163P3CRITICALCVSS 9.0≥ 5.1.0, ≤ 5.1.64≥ 5.5.0, ≤ 5.5.262012-10-17
CVE-2012-3163 [CRITICAL] CVE-2012-3163: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
nvd
CVE-2008-3963P4MEDIUMCVSS 4.0PoCv5.0.0v5.0.6+40 more2008-09-11
CVE-2008-3963 [MEDIUM] CWE-134 CVE-2008-3963: MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b s MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
nvd
CVE-2012-5383P4MEDIUMCVSS 6.2PoCv5.5.282012-10-11
CVE-2012-5383 [MEDIUM] CVE-2012-5383: Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when i Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the "C:\MySQL\MySQL Server 5.5\bin" directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Tro
nvd
CVE-2010-3680P4MEDIUMCVSS 4.0PoCv5.1v5.1.1+45 more2011-01-11
CVE-2010-3680 [MEDIUM] CVE-2010-3680: Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysql Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with nullable columns while using InnoDB, which triggers an assertion failure.
nvd
CVE-2010-3681P4MEDIUMCVSS 4.0PoCv5.1v5.1.1+50 more2011-01-11
CVE-2010-3681 [MEDIUM] CVE-2010-3681: Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a den Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
nvd
Oracle MySQL vulnerabilities | cvebase