Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 52 of 67
CVE-2015-4913P4LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.45≥ 5.6.0, ≤ 5.6.262015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2015-4730P4MEDIUMCVSS 4.0≤ 5.6.202015-10-21
CVE-2015-4730 [MEDIUM] CVE-2015-4730: Unspecified vulnerability in Oracle MySQL 5.6.20 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.20 and earlier allows remote authenticated users to affect availability via unknown vectors related to Types.
nvd
CVE-2007-6303P4LOWCVSS 3.5v5.0.41v5.1.1+13 more2007-12-10
CVE-2007-6303 [LOW] CVE-2007-6303: MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
nvd
CVE-2016-0665P4MEDIUMCVSS 5.5≥ 5.6.0, ≤ 5.6.28≥ 5.7.0, ≤ 5.7.102016-04-21
CVE-2016-0665 [MEDIUM] CVE-2016-0665: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local use
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption.
nvd
CVE-2016-0658P4MEDIUMCVSS 5.5≤ 5.7.102016-04-21
CVE-2016-0658 [MEDIUM] CVE-2016-0658: Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Optimizer.
nvd
CVE-2016-0653P4MEDIUMCVSS 5.5≤ 5.7.102016-04-21
CVE-2016-0653 [MEDIUM] CVE-2016-0653: Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to FTS.
nvd
CVE-2016-0652P4MEDIUMCVSS 5.5≤ 5.7.102016-04-21
CVE-2016-0652 [MEDIUM] CVE-2016-0652: Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to DML.
nvd
CVE-2018-3174P4MEDIUMCVSS 5.3≥ 5.5.0, ≤ 5.5.61≥ 5.6.0, ≤ 5.6.41+2 more2018-10-17
CVE-2018-3174 [MEDIUM] CVE-2018-3174: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Serv
nvd
CVE-2014-2419P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.35≥ 5.6.0, ≤ 5.6.152014-04-16
CVE-2014-2419 [MEDIUM] CVE-2014-2419: Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.
nvd
CVE-2012-1688P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.61≥ 5.5.0, ≤ 5.5.212012-05-03
CVE-2012-1688 [MEDIUM] CVE-2012-1688: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.
nvd
CVE-2014-2494P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.372014-07-17
CVE-2014-2494 [MEDIUM] CVE-2014-2494: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.
nvd
CVE-2016-8327P4MEDIUMCVSS 4.4≥ 5.6.0, ≤ 5.6.34≥ 5.7.0, ≤ 5.7.162017-01-27
CVE-2016-8327 [MEDIUM] CVE-2016-8327: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2012-3173P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.63≥ 5.5.0, ≤ 5.5.252012-10-17
CVE-2012-3173 [MEDIUM] CVE-2012-3173: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
nvd
CVE-2010-3835P4MEDIUMCVSS 4.0v5.1v5.1.1+53 more2011-01-14
CVE-2010-3835 [MEDIUM] CWE-189 CVE-2010-3835: MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of
MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a logical expression that is calculated and stored in a temporary table for GROUP BY, then causing the expression value to be used after the table is created, which causes the expr
nvd
CVE-2010-3838P4MEDIUMCVSS 4.0v5.1v5.1.1+93 more2011-01-14
CVE-2010-3838 [MEDIUM] CVE-2010-3838: MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users t
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATEST or (2) LEAST function with a mixed list of numeric and LONGBLOB arguments, which is not properly handled when the function's result is "processed using an intermediate temporary t
nvd
CVE-2010-3837P4MEDIUMCVSS 4.0v5.1v5.1.1+93 more2011-01-14
CVE-2010-3837 [MEDIUM] CWE-399 CVE-2010-3837: MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users t
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a prepared statement that uses GROUP_CONCAT with the WITH ROLLUP modifier, probably triggering a use-after-free error when a copied object is modified in a way that also affects the original object.
nvd
CVE-2012-1690P4MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.61≥ 5.5.0, ≤ 5.5.212012-05-03
CVE-2012-1690 [MEDIUM] CVE-2012-1690: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.
nvd
CVE-2012-1757P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.232012-07-17
CVE-2012-1757 [MEDIUM] CVE-2012-1757: Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.5.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2014-0384P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.35≥ 5.6.0, ≤ 5.6.152014-04-16
CVE-2014-0384 [MEDIUM] CVE-2014-0384: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to XML.
nvd
CVE-2019-2634P4MEDIUMCVSS 5.1≥ 8.0.0, ≤ 8.0.152019-04-23
CVE-2019-2634 [MEDIUM] CVE-2019-2634: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can resu
nvd