Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 4 of 67
CVE-2016-9842P3HIGHCVSS 8.8≥ 5.5.0, ≤ 5.5.61≥ 5.6.0, ≤ 5.6.41+2 more2017-05-23
CVE-2016-9842 [HIGH] CWE-1335 CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
nvd
CVE-2016-9840P3HIGHCVSS 8.8≥ 5.5.0, ≤ 5.5.61≥ 5.6.0, ≤ 5.6.41+2 more2017-05-23
CVE-2016-9840 [HIGH] CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by lever
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2019-1559P3MEDIUMCVSS 5.9≥ 5.6.0, ≤ 5.6.43≥ 5.7.0, ≤ 5.7.25+1 more2019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2010-3676P4MEDIUMCVSS 4.0PoCv5.1v5.1.1+45 more2011-01-11
CVE-2010-3676 [MEDIUM] CVE-2010-3676: storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenti
storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (1) innodb_file_format or (2) innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement.
nvd
CVE-2014-6500P3HIGHCVSS 7.5≥ 5.5.0, ≤ 5.5.39≥ 5.6.0, ≤ 5.6.202014-10-15
CVE-2014-6500 [HIGH] CVE-2014-6500: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.
nvd
CVE-2014-6491P3HIGHCVSS 7.5≥ 5.5.0, ≤ 5.5.39≥ 5.6.0, ≤ 5.6.202014-10-15
CVE-2014-6491 [HIGH] CVE-2014-6491: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.
nvd
CVE-2012-0882P3HIGHCVSS 7.5v5.5.0v5.5.1+79 more2012-12-21
CVE-2012-0882 [HIGH] CVE-2012-0882: Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module autho
nvd
CVE-2017-10155P3HIGHCVSS 7.5v5.6.0v5.6.1+51 more2017-10-19
CVE-2017-10155 [HIGH] CVE-2017-10155: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2017-3450P3HIGHCVSS 7.5≥ 5.6.0, ≤ 5.6.35≥ 5.7.0, ≤ 5.7.172017-04-24
CVE-2017-3450 [HIGH] CVE-2017-3450: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2018-3155P3HIGHCVSS 7.7≥ 5.7.0, ≤ 5.7.23≥ 8.0.0, ≤ 8.0.122018-10-17
CVE-2018-3155 [HIGH] CVE-2018-3155: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may
nvd
CVE-2017-3329P3HIGHCVSS 7.5≥ 5.5.0, ≤ 5.5.54≥ 5.6.0, ≤ 5.6.35+1 more2017-04-24
CVE-2017-3329 [HIGH] CVE-2017-3329: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling).
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of
nvd
CVE-2017-3309P3HIGHCVSS 7.7≥ 5.5.0, ≤ 5.5.54≥ 5.6.0, ≤ 5.6.35+1 more2017-04-24
CVE-2017-3309 [HIGH] CVE-2017-3309: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is
nvd
CVE-2017-3308P3HIGHCVSS 7.7≥ 5.5.0, ≤ 5.5.54≥ 5.6.0, ≤ 5.6.35+1 more2017-04-24
CVE-2017-3308 [HIGH] CVE-2017-3308: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MyS
nvd
CVE-2019-2822P3HIGHCVSS 7.5≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2822 [HIGH] CVE-2019-2822: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Admin / InnoDB Clu
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Admin / InnoDB Cluster). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person
nvd
CVE-2010-3678P4MEDIUMCVSS 4.0PoCv5.1v5.1.1+45 more2011-01-11
CVE-2010-3678 [MEDIUM] CWE-399 CVE-2010-3678: Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
nvd
CVE-2020-14663P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14663 [HIGH] CVE-2020-14663: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover o
nvd
CVE-2020-14678P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14678 [HIGH] CVE-2020-14678: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover o
nvd
CVE-2020-14697P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14697 [HIGH] CVE-2020-14697: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover o
nvd
CVE-2020-14828P3HIGHCVSS 7.2≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14828 [HIGH] CVE-2020-14828: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. C
nvd
CVE-2021-2144P3HIGHCVSS 7.2≥ 5.7.0, ≤ 5.7.29≥ 8.0.0, ≤ 8.0.192021-04-22
CVE-2021-2144 [HIGH] CVE-2021-2144: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeo
nvd