Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 6 of 67
CVE-2004-0836P3CRITICALCVSS 10.0≥ 3.20, < 3.23.49≥ 4.0.0, < 4.0.212004-11-03
CVE-2004-0836 [CRITICAL] CWE-119 CVE-2004-0836: Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.4
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).
nvd
CVE-2016-3477P3HIGHCVSS 8.1≥ 5.5.0, ≤ 5.5.49≥ 5.6.0, ≤ 5.6.30+1 more2016-07-21
CVE-2016-3477 [HIGH] CVE-2016-3477: Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and ear
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.
nvd
CVE-2017-10379P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.57≥ 5.6.0, ≤ 5.6.37+1 more2017-10-19
CVE-2017-10379 [MEDIUM] CWE-863 CVE-2017-10379: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks
nvd
CVE-2006-0903P4MEDIUMCVSS 4.6PoCv3.23v3.23.0+111 more2006-02-27
CVE-2006-0903 [MEDIUM] CVE-2006-0903: MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contai
MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_q
nvd
CVE-2020-14827P3MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.31≥ 8.0.0, ≤ 8.0.212020-10-21
CVE-2020-14827 [MEDIUM] CVE-2020-14827: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2016-3492P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.51≥ 5.6.0, ≤ 5.6.32+1 more2016-10-25
CVE-2016-3492 [MEDIUM] CVE-2016-3492: Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and ear
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.
nvd
CVE-2016-5626P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.51≥ 5.6.0, ≤ 5.6.32+1 more2016-10-25
CVE-2016-5626 [MEDIUM] CVE-2016-5626: Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and ear
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
nvd
CVE-2019-2740P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.44≥ 5.7.0, ≤ 5.7.26+1 more2019-07-23
CVE-2019-2740 [MEDIUM] CVE-2019-2740: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-2668P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.58≥ 5.6.0, ≤ 5.6.38+1 more2018-01-18
CVE-2018-2668 [MEDIUM] CVE-2018-2668: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2622P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.58≥ 5.6.0, ≤ 5.6.38+1 more2018-01-18
CVE-2018-2622 [MEDIUM] CVE-2018-2622: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2018-2665P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.58≥ 5.6.0, ≤ 5.6.38+1 more2018-01-18
CVE-2018-2665 [MEDIUM] CVE-2018-2665: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2640P3MEDIUMCVSS 6.5≥ 5.5.0, ≤ 5.5.58≥ 5.6.0, ≤ 5.6.38+1 more2018-01-18
CVE-2018-2640 [MEDIUM] CVE-2018-2640: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2019-2805P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.44≥ 5.7.0, ≤ 5.7.26+1 more2019-07-23
CVE-2019-2805 [MEDIUM] CVE-2019-2805: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2019-2800P3HIGHCVSS 7.1≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2800 [HIGH] CVE-2019-2800: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2019-2974P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.45≥ 5.7.0, ≤ 5.7.27+1 more2019-10-16
CVE-2019-2974 [MEDIUM] CVE-2019-2974: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2020-14765P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.49≥ 5.7.0, ≤ 5.7.31+1 more2020-10-21
CVE-2020-14765 [MEDIUM] CVE-2020-14765: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability c
nvd
CVE-2017-3633P3MEDIUMCVSS 6.5≥ 5.6.0, ≤ 5.6.36≥ 5.7.0, ≤ 5.7.182017-08-08
CVE-2017-3633 [MEDIUM] CVE-2017-3633: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Memcached to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2022-21351P3HIGHCVSS 7.1≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21351 [HIGH] CVE-2022-21351: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2022-21278P3HIGHCVSS 7.1≥ 8.0.0, ≤ 8.0.262022-01-19
CVE-2022-21278 [HIGH] CVE-2022-21278: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2001-1453P4HIGHCVSS 7.5v3.23.322001-02-09
CVE-2001-1453 [HIGH] CVE-2001-1453: Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
nvd