Oracle Mysql Server vulnerabilities

269 known vulnerabilities affecting oracle/mysql_server.

Total CVEs
269
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH18MEDIUM228LOW16

Vulnerabilities

Page 11 of 14
CVE-2021-22926HIGHCVSS 7.5≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22926 [HIGH] CWE-840 CVE-2021-22926: libcurl-using applications can ask for a specific client certificate to be used in a transfer. This libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or with a file name - using the same opt
nvd
CVE-2021-22925MEDIUMCVSS 5.3≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22925 [MEDIUM] CWE-200 CVE-2021-22925: curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revea
nvd
CVE-2021-22923MEDIUMCVSS 5.3≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22923 [MEDIUM] CWE-319 CVE-2021-22923: When curl is instructed to get content using the metalink feature, and a user name and password are When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and witho
nvd
CVE-2021-22922MEDIUMCVSS 6.5≥ 5.7.0, ≤ 5.7.35≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22922 [MEDIUM] CWE-840 CVE-2021-22922: When curl is instructed to download content using the metalink feature, thecontents is verified agai When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several o
nvd
CVE-2021-22924LOWCVSS 3.7≥ 5.7.0, ≤ 5.7.36≥ 8.0.0, ≤ 8.0.262021-08-05
CVE-2021-22924 [LOW] CWE-20 CVE-2021-22924: libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing wrong connections.File paths are, or c
nvd
CVE-2021-36222HIGHCVSS 7.5≥ 8.0.0, ≤ 8.0.262021-07-22
CVE-2021-36222 [HIGH] CWE-476 CVE-2021-36222: ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.
nvd
CVE-2021-2412MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.212021-07-21
CVE-2021-2412 [MEDIUM] CVE-2021-2412: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2426MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2426 [MEDIUM] CVE-2021-2426: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2383MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2383 [MEDIUM] CVE-2021-2383: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2422MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2422 [MEDIUM] CVE-2021-2422: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported version Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2021-2440MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2440 [MEDIUM] CVE-2021-2440: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2021-2417MEDIUMCVSS 6.0≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2417 [MEDIUM] CVE-2021-2417: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2021-2429MEDIUMCVSS 5.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2429 [MEDIUM] CVE-2021-2429: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2021-2418MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2418 [MEDIUM] CVE-2021-2418: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2370MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2370 [MEDIUM] CVE-2021-2370: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2021-2441MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2441 [MEDIUM] CVE-2021-2441: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2385MEDIUMCVSS 5.0≥ 5.7.0, ≤ 5.7.34≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2385 [MEDIUM] CVE-2021-2385: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2021-2372MEDIUMCVSS 4.4≥ 5.7.0, ≤ 5.7.34≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2372 [MEDIUM] CVE-2021-2372: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2021-2427MEDIUMCVSS 4.9≥ 8.0.0, ≤ 8.0.252021-07-21
CVE-2021-2427 [MEDIUM] CVE-2021-2427: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2342MEDIUMCVSS 4.9≥ 5.7.0, ≤ 5.7.34≥ 6.0.0, ≤ 8.0.252021-07-21
CVE-2021-2342 [MEDIUM] CVE-2021-2342: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd