Oracle MySQL vulnerabilities
1,330 known vulnerabilities affecting oracle/mysql.
Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181
Vulnerabilities
Page 61 of 67
CVE-2014-4243P4LOWCVSS 2.8≥ 5.5.0, ≤ 5.5.35≥ 5.6.0, ≤ 5.6.152014-07-17
CVE-2014-4243 [LOW] CVE-2014-4243: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.1
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED.
nvd
CVE-2012-3149P4LOWCVSS 3.5≤ 5.5.26v5.5.0+24 more2012-10-16
CVE-2012-3149 [LOW] CVE-2012-3149: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect confidentiality, related to MySQL Client.
nvd
CVE-2016-0643P4LOWCVSS 3.3≥ 5.5.0, ≤ 5.5.48≥ 5.6.0, ≤ 5.6.29+1 more2016-04-21
CVE-2016-0643 [LOW] CVE-2016-0643: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.
nvd
CVE-2024-21247P4LOWCVSS 3.8≥ 8.0.0, ≤ 8.0.39≥ 8.4.0, ≤ 8.4.2+2 more2024-10-15
CVE-2024-21247 [LOW] CWE-284 CVE-2024-21247: Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulner
nvd
CVE-2017-3653P4LOWCVSS 3.1≥ 5.5.0, ≤ 5.5.56≥ 5.6.0, ≤ 5.6.36+1 more2017-08-08
CVE-2017-3653 [LOW] CVE-2017-3653: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2016-0605P4LOWCVSS 2.1v5.6.262016-01-21
CVE-2016-0605 [LOW] CVE-2016-0605: Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2016-5443P4MEDIUMCVSS 4.7≤ 5.7.122016-07-21
CVE-2016-5443 [MEDIUM] CVE-2016-5443: Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows local users to affect availabili
Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows local users to affect availability via vectors related to Server: Connection.
nvd
CVE-2004-0457P4MEDIUMCVSS 4.6≤ 4.0.202004-09-28
CVE-2004-0457 [MEDIUM] CVE-2004-0457: The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server
The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
nvd
CVE-2021-2087P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.222021-01-20
CVE-2021-2087 [MEDIUM] CVE-2021-2087: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2021-2088P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.222021-01-20
CVE-2021-2088 [MEDIUM] CVE-2021-2088: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2018-2762P4MEDIUMCVSS 4.4≥ 5.7.0, ≤ 5.7.212018-04-19
CVE-2018-2762 [MEDIUM] CVE-2018-2762: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supp
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2012-3197P4LOWCVSS 3.5≥ 5.1.0, ≤ 5.1.64≥ 5.5.0, ≤ 5.5.262012-10-17
CVE-2012-3197 [LOW] CVE-2012-3197: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.
nvd
CVE-2021-35632P4MEDIUMCVSS 4.4≥ 8.0.0, ≤ 8.0.262021-10-20
CVE-2021-35632 [MEDIUM] CVE-2021-35632: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2014-6463P4LOWCVSS 3.3≥ 5.5.0, ≤ 5.5.38≥ 5.6.0, ≤ 5.6.192014-10-15
CVE-2014-6463 [LOW] CVE-2014-6463: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML.
nvd
CVE-2022-21265P4LOWCVSS 3.8≥ 8.0.0, ≤ 8.0.272022-01-19
CVE-2022-21265 [LOW] CVE-2022-21265: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, in
nvd
CVE-2012-2102P4LOWCVSS 3.5v5.1v5.1.1+79 more2012-08-17
CVE-2012-2102 [LOW] CWE-119 CVE-2012-2102: MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denia
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
nvd
CVE-2024-21213P4MEDIUMCVSS 4.2≥ 8.0.0, ≤ 8.0.39≥ 8.4.0, ≤ 8.4.2+2 more2024-10-15
CVE-2024-21213 [MEDIUM] CVE-2024-21213: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require huma
nvd
CVE-2014-0431P4LOWCVSS 3.5≤ 5.6.14v5.6.0+13 more2014-01-15
CVE-2014-0431 [LOW] CVE-2014-0431: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-5881.
nvd
CVE-2013-1567P4LOWCVSS 3.5≤ 5.6.10v5.6.0+9 more2013-04-17
CVE-2013-1567 [LOW] CVE-2013-1567: Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language, a different vulnerability than CVE-2013-2395.
nvd
CVE-2012-3156P4LOWCVSS 3.5≤ 5.5.25v5.5.0+23 more2012-10-16
CVE-2012-3156 [LOW] CVE-2012-3156: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.25 and earlier allows re
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server.
nvd