İçeriğe atla
Noroxi

ClickHouse kayıtları

clickhouse üreticisine ait 25 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%28
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

25 kayıt
  • CVE-2018-14671
    40Planlayın

    In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vu

    KritikCVSS 9,8İstismar yokEPSS %3

    clickhouse · clickhouse15 Ağu 2019

  • CVE-2018-14670
    40Planlayın

    Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.

    KritikCVSS 9,8İstismar yokEPSS %2

    clickhouse · clickhouse15 Ağu 2019

  • CVE-2019-16535
    40Planlayın

    In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve

    KritikCVSS 9,8İstismar yokEPSS %2

    clickhouse · clickhouse30 Ara 2019

  • CVE-2023-47118
    39İzleyin

    Heap buffer overflow in T64 codec decompression

    KritikCVSS 9,8İstismar yokEPSS %0

    clickhouse · clickhouse20 Ara 2023

  • CVE-2021-43304
    36İzleyin

    Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query.

    YüksekCVSS 8,8İstismar yokEPSS %2

    clickhouse · clickhouse14 Mar 2022

  • CVE-2021-43305
    36İzleyin

    Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query.

    YüksekCVSS 8,8İstismar yokEPSS %2

    clickhouse · clickhouse14 Mar 2022

  • CVE-2018-14668
    35İzleyin

    In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which

    YüksekCVSS 8,8İstismar yokEPSS %1

    clickhouse · clickhouse15 Ağu 2019

  • CVE-2024-23689
    35İzleyin

    ClickHouse Client Certificate Password Exposure

    YüksekCVSS 8,8İstismar yokEPSS %1

    clickhouse · java libraries19 Oca 2024

  • CVE-2021-42387
    32İzleyin

    Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.

    YüksekCVSS 8,1İstismar yokEPSS %2

    clickhouse · clickhouse14 Mar 2022

  • CVE-2021-42388
    32İzleyin

    Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.

    YüksekCVSS 8,1İstismar yokEPSS %2

    clickhouse · clickhouse14 Mar 2022

  • CVE-2019-16536
    32İzleyin

    Stack overflow leading to DoS can be triggered by a malicious authenticated client.

    YüksekCVSS 8,2İstismar yokEPSS %1

    clickhouse · clickhouse21 May 2025

  • CVE-2018-14669
    31İzleyin

    ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database

    YüksekCVSS 7,5İstismar yokEPSS %2

    clickhouse · clickhouse15 Ağu 2019

  • CVE-2022-44010
    30İzleyin

    An issue was discovered in ClickHouse before 22.9.1.2603.

    YüksekCVSS 7,5İstismar yokEPSS %1

    clickhouse · clickhouse23 Kas 2023

  • CVE-2023-48298
    30İzleyin

    Integer underflow leading to stack overflow in FPC codec decompression

    YüksekCVSS 7,5İstismar yokEPSS %1

    clickhouse · clickhouse21 Ara 2023

  • CVE-2024-41436
    30İzleyin

    ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.

    YüksekCVSS 7,5İstismar yokEPSS %1

    clickhouse · clickhouse3 Eyl 2024

  • CVE-2023-48704
    30İzleyin

    Unauthenticated heap buffer overflow in Gorrila codec decompression

    YüksekCVSS 7,5İstismar yokEPSS %0

    clickhouse · clickhouse22 Ara 2023

  • CVE-2021-42391
    26İzleyin

    Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query.

    OrtaCVSS 6,5İstismar yokEPSS %1

    clickhouse · clickhouse14 Mar 2022

  • CVE-2021-42390
    26İzleyin

    Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query.

    OrtaCVSS 6,5İstismar yokEPSS %1

    clickhouse · clickhouse14 Mar 2022

  • CVE-2021-42389
    26İzleyin

    Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query.

    OrtaCVSS 6,5İstismar yokEPSS %1

    clickhouse · clickhouse14 Mar 2022

  • CVE-2019-15024
    26İzleyin

    In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available

    OrtaCVSS 6,5İstismar yokEPSS %1

    clickhouse · clickhouse30 Ara 2019

  • CVE-2022-44011
    26İzleyin

    An issue was discovered in ClickHouse before 22.9.1.2603.

    OrtaCVSS 6,5İstismar yokEPSS %1

    clickhouse · clickhouse23 Kas 2023

  • CVE-2025-1386
    23İzleyin

    Query smuggling in ch-go library

    OrtaCVSS 5,9İstismar yokEPSS %0

    clickhouse · ch11 Nis 2025

  • CVE-2018-14672
    22İzleyin

    In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messag

    OrtaCVSS 5,3İstismar yokEPSS %2

    clickhouse · clickhouse15 Ağu 2019

  • CVE-2019-18657
    21İzleyin

    ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

    OrtaCVSS 5,3İstismar yokEPSS %1

    clickhouse · clickhouse31 Eki 2019

  • CVE-2024-22412
    19İzleyin

    ClickHouse's Role-based Access Control is bypassed when query caching is enabled.

    OrtaCVSS 4,9İstismar yokEPSS %1

    clickhouse · clickhouse18 Mar 2024