cbcvebase.

Oracle MySQL vulnerabilities

1,330 known vulnerabilities affecting oracle/mysql.

Total CVEs
1,330
CISA KEV
0
Public exploits
50
Exploited in wild
2
Severity breakdown
CRITICAL12HIGH71MEDIUM1066LOW181

Vulnerabilities

Page 63 of 67
CVE-2018-3066P4LOWCVSS 3.3≥ 5.5.0, ≤ 5.5.60≥ 5.6.0, ≤ 5.6.40+1 more2018-07-18
CVE-2018-3066 [LOW] CVE-2018-3066: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerab
nvd
CVE-2015-2566P4LOWCVSS 2.8≤ 5.6.222015-04-16
CVE-2015-2566 [LOW] CVE-2015-2566: Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2019-2738P4LOWCVSS 3.1≥ 5.6.0, ≤ 5.6.44≥ 5.7.0, ≤ 5.7.26+1 more2019-07-23
CVE-2019-2738 [LOW] CVE-2019-2738: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supp Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2018-2767P4LOWCVSS 3.1≥ 5.5.0, ≤ 5.5.60≥ 5.6.0, ≤ 5.6.40+1 more2018-07-18
CVE-2018-2767 [LOW] CVE-2018-2767: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of t
nvd
CVE-2017-3319P4LOWCVSS 3.1≤ 5.7.162017-01-27
CVE-2017-3319 [LOW] CWE-200 CVE-2017-3319: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: X Plugin). Suppor Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: X Plugin). Supported versions that are affected are 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2015-0511P4LOWCVSS 2.8≤ 5.6.232015-04-16
CVE-2015-0511 [LOW] CVE-2015-0511: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
nvd
CVE-2019-2789P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.162019-07-23
CVE-2019-2789 [LOW] CVE-2019-2789: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2012-0492P4LOWCVSS 2.1v5.1v5.1.1+80 more2012-01-18
CVE-2012-0492 [LOW] CVE-2012-0492: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remot Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0485.
nvd
CVE-2012-0493P4LOWCVSS 2.1v5.5.0v5.5.1+20 more2012-01-18
CVE-2012-0493 [LOW] CVE-2012-0493: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenti Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0495.
nvd
CVE-2012-0075P4LOWCVSS 1.7v5.1v5.1.1+106 more2012-01-18
CVE-2012-0075 [LOW] CVE-2012-0075: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allo Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2019-2535P4MEDIUMCVSS 4.1≥ 8.0.0, ≤ 8.0.132019-01-16
CVE-2019-2535 [MEDIUM] CVE-2019-2535: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2007-2693P4LOWCVSS 3.5v5.1.6v5.1.9+8 more2007-05-16
CVE-2007-2693 [LOW] CVE-2007-2693: MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
nvd
CVE-2020-2694P4LOWCVSS 3.1≥ 8.0.0, ≤ 8.0.182020-01-15
CVE-2020-2694 [LOW] CVE-2020-2694: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.18 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized r
nvd
CVE-2019-2911P4LOWCVSS 2.7≥ 5.6.0, ≤ 5.6.45≥ 5.7.0, ≤ 5.7.27+1 more2019-10-16
CVE-2019-2911 [LOW] CVE-2019-2911: Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2017-3468P4LOWCVSS 3.1≤ 5.7.172017-04-24
CVE-2017-3468 [LOW] CVE-2017-3468: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encrypt Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.7.17 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2024-21231P4LOWCVSS 3.1≥ 8.0.0, ≤ 8.0.39≥ 8.4.0, ≤ 8.4.2+2 more2024-10-15
CVE-2024-21231 [LOW] CWE-400 CVE-2024-21231: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported v Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnera
nvd
CVE-2020-14634P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.202020-07-15
CVE-2020-14634 [LOW] CVE-2020-14634: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a sub
nvd
CVE-2021-2019P4LOWCVSS 2.7≥ 8.0.0, ≤ 8.0.192021-01-20
CVE-2021-2019 [LOW] CVE-2021-2019: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2017-3317P4MEDIUMCVSS 4.0≥ 5.5.0, ≤ 5.5.53≥ 5.6.0, ≤ 5.6.34+1 more2017-01-27
CVE-2017-3317 [MEDIUM] CVE-2017-3317: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versi Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attac
nvd
CVE-2014-0430P4LOWCVSS 2.8≤ 5.6.13v5.6.0+12 more2014-01-15
CVE-2014-0430 [LOW] CVE-2014-0430: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows re Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema.
nvd
Oracle MySQL vulnerabilities | cvebase