cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 60 of 67
CVE-2019-2536P4MEDIUMCVSS 5.0≥ 8.0.0, ≤ 8.0.132019-01-16
CVE-2019-2536 [MEDIUM] CVE-2019-2536: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a
nvd
CVE-2016-0663P4MEDIUMCVSS 4.7≤ 5.7.102016-04-21
CVE-2016-0663 [MEDIUM] CVE-2016-0663: Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availabili Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Performance Schema.
nvd
CVE-2010-3834P4MEDIUMCVSS 4.0v5.1v5.1.1+93 more2011-01-14
CVE-2010-3834 [MEDIUM] CVE-2010-3834: Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
nvd
CVE-2005-0004P4MEDIUMCVSS 4.6≥ 4.0.0, < 4.0.23≥ 4.1.0, < 4.1.10+1 more2005-04-14
CVE-2005-0004 [MEDIUM] CWE-59 CVE-2005-0004: The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and oth The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
nvd
CVE-2016-8289P4MEDIUMCVSS 4.7≤ 5.7.132016-10-25
CVE-2016-8289 [MEDIUM] CWE-264 CVE-2016-8289: Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows local users to affect integrity Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows local users to affect integrity and availability via vectors related to Server: InnoDB.
nvd
CVE-2012-3167P4LOWCVSS 3.5≥ 5.1.0, ≤ 5.1.63≥ 5.5.0, ≤ 5.5.252012-10-17
CVE-2012-3167 [LOW] CVE-2012-3167: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.
nvd
CVE-2004-0837P4LOWCVSS 2.6≥ 3.20, < 3.23.49≥ 4.0.0, < 4.0.212004-11-03
CVE-2004-0837 [LOW] CVE-2004-0837: MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (cras MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
nvd
CVE-2019-2797P4MEDIUMCVSS 4.2≥ 5.7.0, ≤ 5.7.26≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2797 [MEDIUM] CVE-2019-2797: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise
nvd
CVE-2014-0393P4LOWCVSS 3.3≥ 5.1.0, ≤ 5.1.71≥ 5.5.0, ≤ 5.5.33+1 more2014-01-15
CVE-2014-0393 [LOW] CVE-2014-0393: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 a Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect integrity via unknown vectors related to InnoDB.
nvd
CVE-2014-4214P4LOWCVSS 3.3≤ 5.6.17v5.6.0+16 more2014-07-17
CVE-2014-4214 [LOW] CVE-2014-4214: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP.
nvd
CVE-2014-2442P4MEDIUMCVSS 4.0≤ 5.6.15v5.6.0+14 more2014-04-16
CVE-2014-2442 [MEDIUM] CVE-2014-2442: Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to MyISAM.
nvd
CVE-2021-1998P4LOWCVSS 3.8≥ 8.0.0, ≤ 8.0.202021-01-20
CVE-2021-1998 [LOW] CVE-2021-1998: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, inse
nvd
CVE-2017-10365P4LOWCVSS 3.8≥ 5.7.0, ≤ 5.7.182017-10-19
CVE-2017-10365 [LOW] CVE-2017-10365: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized updat
nvd
CVE-2012-0112P4LOWCVSS 3.5v5.1v5.1.1+80 more2012-01-18
CVE-2012-0112 [LOW] CVE-2012-0112: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remot Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492.
nvd
CVE-2014-0427P4LOWCVSS 3.5≤ 5.6.13v5.6.0+12 more2014-01-15
CVE-2014-0427 [LOW] CVE-2014-0427: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote authenticated users to affect availability via vectors related to FTS.
nvd
CVE-2019-2791P4LOWCVSS 3.8≥ 5.7.0, ≤ 5.7.26≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2791 [LOW] CVE-2019-2791: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Plug-in). S Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Plug-in). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resu
nvd
CVE-2014-0420P4LOWCVSS 2.8≥ 5.5.0, ≤ 5.5.34≥ 5.6.0, ≤ 5.6.142014-01-15
CVE-2014-0420 [LOW] CVE-2014-0420: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.34 and earlier, and 5.6. Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.34 and earlier, and 5.6.14 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Replication.
nvd
CVE-2015-0506P4LOWCVSS 3.5≤ 5.6.232015-04-16
CVE-2015-0506 [LOW] CVE-2015-0506: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2015-0508.
nvd
CVE-2013-1548P4LOWCVSS 3.5≥ 5.6.0, ≤ 5.6.47≥ 5.7.0, ≤ 5.7.29+1 more2013-04-17
CVE-2013-1548 [LOW] CVE-2013-1548: Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Types.
nvd
CVE-2014-2432P4LOWCVSS 2.8≥ 5.5.0, ≤ 5.5.35≥ 5.6.0, ≤ 5.6.152014-04-16
CVE-2014-2432 [LOW] CVE-2014-2432: Unspecified vulnerability Oracle the MySQL Server component 5.5.35 and earlier and 5.6.15 and earlie Unspecified vulnerability Oracle the MySQL Server component 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Federated.
nvd
Oracle MySQL vulnerabilities | cvebase