cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 58 of 67
CVE-2013-3796P4MEDIUMCVSS 4.0≤ 5.6.11v5.6.0+10 more2013-07-17
CVE-2013-3796 [MEDIUM] CVE-2013-3796: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
nvd
CVE-2013-3806P4MEDIUMCVSS 4.0≤ 5.6.11v5.6.0+10 more2013-07-17
CVE-2013-3806 [MEDIUM] CVE-2013-3806: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3811.
nvd
CVE-2013-3795P4MEDIUMCVSS 4.0≤ 5.6.11v5.6.0+10 more2013-07-17
CVE-2013-3795 [MEDIUM] CVE-2013-3795: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.
nvd
CVE-2014-2435P4MEDIUMCVSS 4.0≤ 5.6.15v5.6.0+14 more2014-04-16
CVE-2014-2435 [MEDIUM] CVE-2014-2435: Unspecified vulnerability in Oracle MySQL Server 5.6.16 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.16 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2015-4807P4LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.45≥ 5.6.0, ≤ 5.6.262015-10-21
CVE-2015-4807 [LOW] CVE-2015-4807: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier, when run Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier, when running on Windows, allows remote authenticated users to affect availability via unknown vectors related to Server : Query Cache.
nvd
CVE-2025-50103P4MEDIUMCVSS 4.4≥ 9.0.0, ≤ 9.3.02025-07-15
CVE-2025-50103 [MEDIUM] CWE-400 CVE-2025-50103: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2017-3650P4LOWCVSS 3.7≤ 5.7.182017-08-08
CVE-2017-3650 [LOW] CVE-2017-3650: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: C API). Supported version Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: C API). Supported versions that are affected are 5.7.18 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to
nvd
CVE-2017-3467P4LOWCVSS 3.7≤ 5.7.172017-04-24
CVE-2017-3467 [LOW] CVE-2017-3467: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.7.17 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read a
nvd
CVE-2013-5908P4LOWCVSS 2.6≥ 5.1.0, ≤ 5.1.72≥ 5.5.0, ≤ 5.5.34+1 more2014-01-15
CVE-2013-5908 [LOW] CVE-2013-5908: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.
nvd
CVE-2015-2639P4LOWCVSS 3.5≤ 5.6.242015-07-16
CVE-2015-2639 [LOW] CVE-2015-2639: Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Firewall.
nvd
CVE-2015-4836P4LOWCVSS 2.8≥ 5.5.0, ≤ 5.5.45≥ 5.6.0, ≤ 5.6.262015-10-21
CVE-2015-4836 [LOW] CVE-2015-4836: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
nvd
CVE-2012-5096P4LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.282013-01-17
CVE-2012-5096 [LOW] CVE-2012-5096: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote a Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.
nvd
CVE-2015-4791P4LOWCVSS 3.5≤ 5.6.262015-10-21
CVE-2015-4791 [LOW] CVE-2015-4791: Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2005-0799P4MEDIUMCVSS 5.0v4.1.92005-03-15
CVE-2005-0799 [MEDIUM] CVE-2005-0799: MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.
nvd
CVE-2016-0661P4MEDIUMCVSS 4.7≥ 5.6.0, ≤ 5.6.28≥ 5.7.0, ≤ 5.7.102016-04-21
CVE-2016-0661 [MEDIUM] CVE-2016-0661: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local use Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
nvd
CVE-2010-3836P4MEDIUMCVSS 4.0v5.1v5.1.1+93 more2011-01-14
CVE-2010-3836 [MEDIUM] CWE-399 CVE-2010-3836: MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users t MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors related to view preparation, pre-evaluation of LIKE predicates, and IN Optimizers.
nvd
CVE-2010-3677P4MEDIUMCVSS 4.0v5.1.1v5.1.2+81 more2011-01-11
CVE-2010-3677 [MEDIUM] CWE-399 CVE-2010-3677: Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a de Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column.
nvd
CVE-2012-3144P4MEDIUMCVSS 4.0≤ 5.5.26v5.5.0+24 more2012-10-16
CVE-2012-3144 [MEDIUM] CVE-2012-3144: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.
nvd
CVE-2014-2438P4LOWCVSS 3.5≥ 5.5.0, ≤ 5.5.35≥ 5.6.0, ≤ 5.6.152014-04-16
CVE-2014-2438 [LOW] CVE-2014-2438: Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Replication.
nvd
CVE-2012-2749P4MEDIUMCVSS 4.0v5.1v5.1.1+82 more2012-08-17
CVE-2012-2749 [MEDIUM] CWE-399 CVE-2012-2749: MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denia MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
nvd
Oracle MySQL vulnerabilities | cvebase