Oracle MySQL vulnerabilities

1,328 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,328
CISA KEV
0
Public exploits
50
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH71MEDIUM1064LOW181

Vulnerabilities

Page 58 of 67
CVE-2013-1502LOWCVSS 1.5≥ 5.5.0, ≤ 5.5.30≥ 5.6.0, ≤ 5.6.92013-04-17
CVE-2013-1502 [LOW] CVE-2013-1502: Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.9 and earlier allows local user Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.9 and earlier allows local users to affect availability via unknown vectors related to Server Partition.
nvd
CVE-2013-2391LOWCVSS 3.0≥ 5.1.0, ≤ 5.1.71≥ 5.5.0, ≤ 5.5.33+1 more2013-04-17
CVE-2013-2391 [LOW] CVE-2013-2391: Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and ear Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to Server Install.
nvd
CVE-2013-1567LOWCVSS 3.5≤ 5.6.10v5.6.0+9 more2013-04-17
CVE-2013-1567 [LOW] CVE-2013-1567: Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language, a different vulnerability than CVE-2013-2395.
nvd
CVE-2013-2381LOWCVSS 3.5≤ 5.6.10v5.1.51+46 more2013-04-17
CVE-2013-2381 [LOW] CVE-2013-2381: Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server Privileges.
nvd
CVE-2013-1511LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.30≥ 5.6.0, ≤ 5.6.102013-04-17
CVE-2013-1511 [LOW] CVE-2013-1511: Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote au Unspecified vulnerability in Oracle MySQL 5.5.30 and earlier and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2013-1548LOWCVSS 3.5≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2013-04-17
CVE-2013-1548 [LOW] CVE-2013-1548: Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Types.
nvd
CVE-2013-1506LOWCVSS 2.8≥ 5.1.0, ≤ 5.1.67≥ 5.5.0, ≤ 5.5.29+1 more2013-04-17
CVE-2013-1506 [LOW] CVE-2013-1506: Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and ear Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Locking.
nvd
CVE-2013-1566LOWCVSS 3.5≤ 5.6.10v5.6.0+9 more2013-04-17
CVE-2013-1566 [LOW] CVE-2013-1566: Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2013-1492HIGHCVSS 7.5v5.1v5.1.1+93 more2013-03-28
CVE-2013-1492 [HIGH] CVE-2013-1492: Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecif Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulnerability than CVE-2012-0553.
nvd
CVE-2012-0553HIGHCVSS 7.5v5.1v5.1.1+91 more2013-03-28
CVE-2012-0553 [HIGH] CWE-119 CVE-2012-0553: Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecif Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492.
nvd
CVE-2013-1861MEDIUMCVSS 5.0PoC≥ 5.1.0, ≤ 5.1.69≥ 5.5.0, ≤ 5.5.31+1 more2013-03-28
CVE-2013-1861 [MEDIUM] CWE-119 CVE-2013-1861: MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing
nvd
CVE-2012-4414MEDIUMCVSS 6.5≤ 5.5.28v5.1.51+34 more2013-01-22
CVE-2012-4414 [MEDIUM] CWE-89 CVE-2012-4414: Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.2 Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not comme
nvd
CVE-2012-1702MEDIUMCVSS 5.0≥ 5.1.0, ≤ 5.1.66≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2012-1702 [MEDIUM] CVE-2012-1702: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2013-0386MEDIUMCVSS 6.8≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2013-0386 [MEDIUM] CVE-2013-0386: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
nvd
CVE-2013-0371MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2013-0371 [MEDIUM] CVE-2013-0371: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
nvd
CVE-2013-0385MEDIUMCVSS 6.6≥ 5.1.0, ≤ 5.1.66≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2013-0385 [MEDIUM] CVE-2013-0385: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.
nvd
CVE-2013-0367MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2013-0367 [MEDIUM] CVE-2013-0367: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
nvd
CVE-2012-0574MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.66≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2012-0574 [MEDIUM] CVE-2012-0574: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2012-5060MEDIUMCVSS 6.8≥ 5.1.0, ≤ 5.1.65≥ 5.5.0, ≤ 5.5.272013-01-17
CVE-2012-5060 [MEDIUM] CVE-2012-5060: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
nvd
CVE-2012-0578MEDIUMCVSS 4.0≥ 5.1.0, ≤ 5.1.66≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2012-0578 [MEDIUM] CVE-2012-0578: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd