cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 57 of 67
CVE-2020-2922P4LOWCVSS 3.7≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2020-04-15
CVE-2020-2922 [LOW] CVE-2020-2922: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can resul
nvd
CVE-2021-2007P4LOWCVSS 3.7≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2021-01-20
CVE-2021-2007 [LOW] CVE-2021-2007: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can resul
nvd
CVE-2016-0610P4LOWCVSS 3.5≤ 5.6.272016-01-21
CVE-2016-0610 [LOW] CVE-2016-0610: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x b Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2015-2567P4LOWCVSS 3.5≤ 5.6.232015-04-16
CVE-2015-2567 [LOW] CVE-2015-2567: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2017-10268P4MEDIUMCVSS 4.1≥ 5.5.0, ≤ 5.5.57≥ 5.6.0, ≤ 5.6.37+1 more2017-10-19
CVE-2017-10268 [MEDIUM] CVE-2017-10268: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Su
nvd
CVE-2022-39404P4MEDIUMCVSS 4.2≤ 1.6.32022-10-18
CVE-2022-39404 [MEDIUM] CVE-2022-39404: Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Suppor Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Supported versions that are affected are 1.6.3 and prior. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Installer executes to compromise MySQL Installer. Successful attacks require human interaction f
nvd
CVE-2004-0956P4MEDIUMCVSS 5.0v4.0.0v4.0.1+17 more2005-01-10
CVE-2004-0956 [MEDIUM] CVE-2004-0956: MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a M MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
nvd
CVE-2002-1373P4MEDIUMCVSS 5.0v3.22.26v3.22.27+45 more2002-12-23
CVE-2002-1373 [MEDIUM] CVE-2002-1373: Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows re Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.
nvd
CVE-2003-0073P4MEDIUMCVSS 5.0v3.23.31v3.23.36+6 more2003-02-19
CVE-2003-0073 [MEDIUM] CVE-2003-0073: Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to c Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.
nvd
CVE-2015-4792P4LOWCVSS 1.7≥ 5.5.0, ≤ 5.5.45≥ 5.6.0, ≤ 5.6.262015-10-21
CVE-2015-4792 [LOW] CVE-2015-4792: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.
nvd
CVE-2012-1697P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.212012-05-03
CVE-2012-1697 [MEDIUM] CVE-2012-1697: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.21 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.
nvd
CVE-2012-0119P4MEDIUMCVSS 4.0v5.1v5.1.1+80 more2012-01-18
CVE-2012-0119 [MEDIUM] CVE-2012-0119: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remot Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
nvd
CVE-2012-0115P4MEDIUMCVSS 4.0v5.1v5.1.1+80 more2012-01-18
CVE-2012-0115 [MEDIUM] CVE-2012-0115: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remot Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
nvd
CVE-2012-0120P4MEDIUMCVSS 4.0v5.1v5.1.1+80 more2012-01-18
CVE-2012-0120 [MEDIUM] CVE-2012-0120: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remot Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0485, and CVE-2012-0492.
nvd
CVE-2012-0495P4MEDIUMCVSS 4.0v5.5.0v5.5.1+20 more2012-01-18
CVE-2012-0495 [MEDIUM] CVE-2012-0495: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenti Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0493.
nvd
CVE-2013-3805P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.30≥ 5.6.0, ≤ 5.6.102013-07-17
CVE-2013-3805 [MEDIUM] CVE-2013-3805: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.1 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements.
nvd
CVE-2013-1512P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.292013-04-17
CVE-2013-1512 [MEDIUM] CVE-2013-1512: Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.5.29 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
nvd
CVE-2012-1696P4MEDIUMCVSS 4.0≤ 5.5.19v3.20+199 more2012-05-03
CVE-2012-1696 [MEDIUM] CVE-2012-1696: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2012-0583P4MEDIUMCVSS 4.0≤ 5.1.60v5.1+76 more2012-05-03
CVE-2012-0583 [MEDIUM] CVE-2012-0583: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.
nvd
CVE-2006-4226P4LOWCVSS 3.6v4.0.0v4.0.1+66 more2006-08-18
CVE-2006-4226 [LOW] CVE-2006-4226: MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystem MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
nvd