mysql kayıtları
mysql üreticisine ait 112 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %2,7
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %75,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-399 Resource Management Errors7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-20 Improper Input Validation4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-134 Use of Externally-Controlled Format String3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
112 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2006-4305Silahlaştırılmış | Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connectmysql · maxdb | Kritik10,0 | — | %71,7 | 29 Ağu 2006 |
61Bu hafta | CVE-2004-0627Kavram kanıtı | The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrmysql · mysql | Kritik10,0 | — | %69,6 | 6 Ara 2004 |
61Bu hafta | CVE-2005-0684Silahlaştırılmış | Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTPmysql · maxdb | Kritik10,0 | — | %68,5 | 25 Nis 2005 |
60Bu hafta | CVE-2003-0780Kavram kanıtı | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privilmysql · mysql | Kritik9,0 | — | %78,4 | 22 Eyl 2003 |
57Planlayın | CVE-2008-0226Silahlaştırılmış | Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitryassl · yassl · CWE-119 | Yüksek7,5 | — | %91,6 | 10 Oca 2008 |
42Planlayın | CVE-2004-0628İstismar yok | Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly mysql · mysql | Kritik10,0 | — | %7,8 | 6 Ara 2004 |
41Planlayın | CVE-2004-1168İstismar yok | Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code mysql · maxdb | Kritik10,0 | — | %4,6 | 10 Oca 2005 |
41Planlayın | CVE-2005-1274İstismar yok | Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers mysql · maxdb | Kritik10,0 | — | %4,2 | 26 Nis 2005 |
38İzleyin | CVE-2006-1518Kavram kanıtı | Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary codemysql · mysql | Orta6,5 | — | %38,4 | 5 May 2006 |
37İzleyin | CVE-2004-0835Kavram kanıtı | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original tablemysql · mysql | Yüksek7,5 | — | %22,4 | 3 Kas 2004 |
37İzleyin | CVE-2009-2446Kavram kanıtı | Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 almysql · mysql · CWE-134 | Yüksek8,5 | — | %10,6 | 13 Tem 2009 |
32İzleyin | CVE-2007-5969İstismar yok | MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4mysql · mysql server · CWE-264 | Yüksek7,1 | — | %14,3 | 10 Ara 2007 |
32İzleyin | CVE-2012-0882İstismar yok | Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows mysql · mysql · CWE-119 | Yüksek7,5 | — | %5,3 | 21 Ara 2012 |
31İzleyin | CVE-2006-1516Kavram kanıtı | The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackermysql · mysql | Orta5,0 | — | %35,8 | 5 May 2006 |
31İzleyin | CVE-2010-1850İstismar yok | Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELmysql · mysql · CWE-119 | Orta6,0 | — | %21,8 | 7 Haz 2010 |
31İzleyin | CVE-2005-0111İstismar yok | Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long pasmysql · maxdb | Yüksek7,5 | — | %3,8 | 13 Oca 2005 |
31İzleyin | CVE-2006-2753İstismar yok | SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQLmysql · mysql | Yüksek7,5 | — | %3,5 | 1 Haz 2006 |
31İzleyin | CVE-2013-1492İstismar yok | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a differemysql · mysql · CWE-119 | Yüksek7,5 | — | %2,8 | 28 Mar 2013 |
31İzleyin | CVE-2012-0553İstismar yok | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a differemysql · mysql · CWE-119 | Yüksek7,5 | — | %2,6 | 28 Mar 2013 |
31İzleyin | CVE-2009-2942İstismar yok | The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers tmysql-ocaml · mysql-ocaml | Yüksek7,5 | — | %2,3 | 22 Eki 2009 |
31İzleyin | CVE-2017-15945İstismar yok | The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera mariadb · mariadb · CWE-732 | Yüksek7,8 | — | %0,4 | 27 Eki 2017 |
30İzleyin | CVE-2006-4227Kavram kanıtı | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of tmysql · mysql · CWE-20 | Orta6,5 | — | %13,6 | 18 Ağu 2006 |
29İzleyin | CVE-2009-5026Kavram kanıtı | The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which tmysql · mysql · CWE-89 | Orta6,8 | — | %7,8 | 16 Ağu 2012 |
28İzleyin | CVE-2009-4028İstismar yok | The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a mysql · mysql · CWE-20 | Orta6,8 | — | %1,8 | 30 Kas 2009 |
27İzleyin | CVE-2010-1848İstismar yok | Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended tabmysql · mysql · CWE-22 | Orta6,5 | — | %3,1 | 7 Haz 2010 |
- CVE-2006-430562Bu hafta
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connect
KritikCVSS 10,0SilahlaştırılmışEPSS %72mysql · maxdb29 Ağu 2006
- CVE-2004-062761Bu hafta
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scr
KritikCVSS 10,0Kavram kanıtıEPSS %70mysql · mysql6 Ara 2004
- CVE-2005-068461Bu hafta
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP
KritikCVSS 10,0SilahlaştırılmışEPSS %69mysql · maxdb25 Nis 2005
- CVE-2003-078060Bu hafta
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privil
KritikCVSS 9,0Kavram kanıtıEPSS %78mysql · mysql22 Eyl 2003
- CVE-2008-022657Planlayın
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitr
YüksekCVSS 7,5SilahlaştırılmışEPSS %92yassl · yassl10 Oca 2008
- CVE-2004-062842Planlayın
Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly
KritikCVSS 10,0İstismar yokEPSS %8mysql · mysql6 Ara 2004
- CVE-2004-116841Planlayın
Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code
KritikCVSS 10,0İstismar yokEPSS %5mysql · maxdb10 Oca 2005
- CVE-2005-127441Planlayın
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers
KritikCVSS 10,0İstismar yokEPSS %4mysql · maxdb26 Nis 2005
- CVE-2006-151838İzleyin
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code
OrtaCVSS 6,5Kavram kanıtıEPSS %38mysql · mysql5 May 2006
- CVE-2004-083537İzleyin
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table
YüksekCVSS 7,5Kavram kanıtıEPSS %22mysql · mysql3 Kas 2004
- CVE-2009-244637İzleyin
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 al
YüksekCVSS 8,5Kavram kanıtıEPSS %11mysql · mysql13 Tem 2009
- CVE-2007-596932İzleyin
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4
YüksekCVSS 7,1İstismar yokEPSS %14mysql · mysql server10 Ara 2007
- CVE-2012-088232İzleyin
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows
YüksekCVSS 7,5İstismar yokEPSS %5mysql · mysql21 Ara 2012
- CVE-2006-151631İzleyin
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attacker
OrtaCVSS 5,0Kavram kanıtıEPSS %36mysql · mysql5 May 2006
- CVE-2010-185031İzleyin
Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIEL
OrtaCVSS 6,0İstismar yokEPSS %22mysql · mysql7 Haz 2010
- CVE-2005-011131İzleyin
Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long pas
YüksekCVSS 7,5İstismar yokEPSS %4mysql · maxdb13 Oca 2005
- CVE-2006-275331İzleyin
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL
YüksekCVSS 7,5İstismar yokEPSS %4mysql · mysql1 Haz 2006
- CVE-2013-149231İzleyin
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a differe
YüksekCVSS 7,5İstismar yokEPSS %3mysql · mysql28 Mar 2013
- CVE-2012-055331İzleyin
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a differe
YüksekCVSS 7,5İstismar yokEPSS %3mysql · mysql28 Mar 2013
- CVE-2009-294231İzleyin
The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %2mysql-ocaml · mysql-ocaml22 Eki 2009
- CVE-2017-1594531İzleyin
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera
YüksekCVSS 7,8İstismar yokEPSS %0mariadb · mariadb27 Eki 2017
- CVE-2006-422730İzleyin
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of t
OrtaCVSS 6,5Kavram kanıtıEPSS %14mysql · mysql18 Ağu 2006
- CVE-2009-502629İzleyin
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which t
OrtaCVSS 6,8Kavram kanıtıEPSS %8mysql · mysql16 Ağu 2012
- CVE-2009-402828İzleyin
The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a
OrtaCVSS 6,8İstismar yokEPSS %2mysql · mysql30 Kas 2009
- CVE-2010-184827İzleyin
Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended tab
OrtaCVSS 6,5İstismar yokEPSS %3mysql · mysql7 Haz 2010