Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 5 of 67
CVE-2016-9843P3CRITICALCVSS 9.8≥ 5.5.0, ≤ 5.5.61≥ 5.6.0, ≤ 5.6.41+2 more2017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unsp
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
nvd
CVE-2020-11080P3HIGHCVSS 7.5≥ 7.3.0, ≤ 7.3.30≥ 7.4.0, ≤ 7.4.29+3 more2020-06-03
CVE-2020-11080 [HIGH] CWE-707 CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of se
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vul
nvd
CVE-2020-14878P3HIGHCVSS 8.0≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14878 [HIGH] CVE-2020-14878: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Succ
nvd
CVE-2014-0001P3HIGHCVSS 7.5v5.5.0v5.5.1+51 more2014-01-31
CVE-2014-0001 [HIGH] CWE-119 CVE-2014-0001: Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database
Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.
nvd
CVE-2001-0407P4MEDIUMCVSS 4.6PoC≤ 3.23.362001-06-27
CVE-2001-0407 [MEDIUM] CVE-2001-0407: Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary fil
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
nvd
CVE-2012-3158P3HIGHCVSS 7.5≥ 5.1.0, ≤ 5.1.64≥ 5.5.0, ≤ 5.5.262012-10-16
CVE-2012-3158 [HIGH] CVE-2012-3158: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Protocol.
nvd
CVE-2019-2534P3HIGHCVSS 7.1≥ 5.6.0, ≤ 5.6.42≥ 5.7.0, ≤ 5.7.24+1 more2019-01-16
CVE-2019-2534 [HIGH] CVE-2019-2534: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2009-0819P4MEDIUMCVSS 4.0PoCv5.1v5.1.1+29 more2009-03-05
CVE-2009-0819 [MEDIUM] CVE-2009-0819: sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated use
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.
nvd
CVE-2022-21600P3HIGHCVSS 7.2≥ 8.0, ≤ 8.0.272022-10-18
CVE-2022-21600 [HIGH] CVE-2022-21600: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Serv
nvd
CVE-2017-3302P3HIGHCVSS 7.5≥ 5.6.0, < 5.6.21≥ 5.7.0, < 5.7.52017-02-12
CVE-2017-3302 [HIGH] CWE-416 CVE-2017-3302: Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through
Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.
nvd
CVE-2023-21887P4MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.312023-01-18
CVE-2023-21887 [MEDIUM] CVE-2023-21887: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2012-4414P3MEDIUMCVSS 6.5≤ 5.5.28v5.1.51+34 more2013-01-22
CVE-2012-4414 [MEDIUM] CWE-89 CVE-2012-4414: Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.2
Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not comme
nvd
CVE-2003-1480P4MEDIUMCVSS 4.3PoCv3.20v3.20.32a+62 more2003-12-31
CVE-2003-1480 [MEDIUM] CWE-310 CVE-2003-1480: MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attac
MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.
nvd
CVE-2016-3440P3HIGHCVSS 7.7≤ 5.7.112016-07-21
CVE-2016-3440 [HIGH] CVE-2016-3440: Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.
nvd
CVE-2006-2753P3HIGHCVSS 7.5v4.1.1v4.1.4+20 more2006-06-01
CVE-2006-2753 [HIGH] CVE-2006-2753: SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-depe
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
nvd
CVE-2018-2562P3HIGHCVSS 7.1≥ 5.5.0, ≤ 5.5.58≥ 5.6.0, ≤ 5.6.38+1 more2018-01-18
CVE-2018-2562 [HIGH] CVE-2018-2562: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supp
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2018-3064P3HIGHCVSS 7.1≥ 5.6.0, ≤ 5.6.40≥ 5.7.0, ≤ 5.7.22+1 more2018-07-18
CVE-2018-3064 [HIGH] CVE-2018-3064: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2007-2583P4MEDIUMCVSS 4.0PoCfixed in 5.0.40≥ 5.1, ≤ 5.1.172007-05-10
CVE-2007-2583 [MEDIUM] CVE-2007-2583: The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta,
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
nvd
CVE-2021-35610P3HIGHCVSS 7.1≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35610 [HIGH] CVE-2021-35610: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2008-4456P4LOWCVSS 2.6PoCv5.0.26v5.0.27+9 more2008-10-06
CVE-2008-4456 [LOW] CWE-79 CVE-2008-4456: Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45,
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE
nvd