Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 50 of 67
CVE-2016-0651P4MEDIUMCVSS 5.5≥ 5.5.0, ≤ 5.5.462016-04-21
CVE-2016-0651 [MEDIUM] CVE-2016-0651: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors related to Optimizer.
nvd
CVE-2016-0656P4MEDIUMCVSS 5.5≤ 5.7.102016-04-21
CVE-2016-0656 [MEDIUM] CVE-2016-0656: Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0654.
nvd
CVE-2016-0654P4MEDIUMCVSS 5.5≤ 5.7.102016-04-21
CVE-2016-0654 [MEDIUM] CVE-2016-0654: Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0656.
nvd
CVE-2017-3648P4MEDIUMCVSS 4.4≥ 5.5.0, ≤ 5.5.56≥ 5.6.0, ≤ 5.6.36+1 more2017-08-08
CVE-2017-3648 [MEDIUM] CVE-2017-3648: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Suppor
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of thi
nvd
CVE-2017-3647P4MEDIUMCVSS 4.4≥ 5.6.0, ≤ 5.6.36≥ 5.7.0, ≤ 5.7.182017-08-08
CVE-2017-3647 [MEDIUM] CVE-2017-3647: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2017-3649P4MEDIUMCVSS 4.4≥ 5.6.0, ≤ 5.6.36≥ 5.7.0, ≤ 5.7.182017-08-08
CVE-2017-3649 [MEDIUM] CVE-2017-3649: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2019-3009P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.172019-10-16
CVE-2019-3009 [MEDIUM] CVE-2019-3009: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection). Supported versions that are affected are 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2018-3283P4MEDIUMCVSS 4.4≥ 5.7.0, ≤ 5.7.23≥ 8.0.0, ≤ 8.0.122018-10-17
CVE-2018-3283 [MEDIUM] CVE-2018-3283: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2017-10286P4MEDIUMCVSS 4.4≥ 5.6.0, ≤ 5.6.37≥ 5.7.0, ≤ 5.7.192017-10-19
CVE-2017-10286 [MEDIUM] CVE-2017-10286: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2010-3840P4MEDIUMCVSS 4.0v5.1v5.1.1+47 more2011-01-14
CVE-2010-3840 [MEDIUM] CVE-2010-3840: The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remo
The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.
nvd
CVE-2014-0402P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.71≥ 5.5.0, ≤ 5.5.33+1 more2014-01-15
CVE-2014-0402 [MEDIUM] CVE-2014-0402: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 a
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.
nvd
CVE-2014-0386P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.71≥ 5.5.0, ≤ 5.5.33+1 more2014-01-15
CVE-2014-0386 [MEDIUM] CVE-2014-0386: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 a
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2014-0412P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.72≥ 5.5.0, ≤ 5.5.34+1 more2014-01-15
CVE-2014-0412 [MEDIUM] CVE-2014-0412: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 a
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2018-3284P4MEDIUMCVSS 4.4≥ 5.7.0, ≤ 5.7.23≥ 8.0.0, ≤ 8.0.122018-10-17
CVE-2018-3284 [MEDIUM] CVE-2018-3284: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2020-14873P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14873 [MEDIUM] CVE-2020-14873: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abilit
nvd
CVE-2013-3802P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.69≥ 5.5.0, ≤ 5.5.31+1 more2013-07-17
CVE-2013-3802 [MEDIUM] CVE-2013-3802: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 a
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.
nvd
CVE-2015-4772P4MEDIUMCVSS 4.0≤ 5.6.242015-07-16
CVE-2015-4772 [MEDIUM] CVE-2015-4772: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.
nvd
CVE-2019-3018P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.172019-10-16
CVE-2019-3018 [MEDIUM] CVE-2019-3018: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2013-3839P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.70≥ 5.5.0, ≤ 5.5.32+1 more2013-10-16
CVE-2013-3839 [MEDIUM] CVE-2013-3839: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 a
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-4756P4MEDIUMCVSS 4.0≤ 5.6.222015-07-16
CVE-2015-4756 [MEDIUM] CVE-2015-4756: Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-0439.
nvd