Skip to content
Noroxi

Percona records

21 published records for vendor percona.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
57.1%
Median publish → KEV
No record has entered KEV

All records

21 records
  • Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    oracle · mysqlSep 20, 2016

  • A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.

    HighCVSS 7.2Proof of conceptEPSS 38%

    mariadb · mariadbMar 18, 2021

  • The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank

    CriticalCVSS 9.8No exploitEPSS 2%

    percona · percona serverMay 23, 2019

  • An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in

    CriticalCVSS 9.8No exploitEPSS 2%

    percona · percona serverNov 9, 2020

  • In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize

    CriticalCVSS 9.8No exploitEPSS 1%

    percona · monitoring and managementJun 6, 2023

  • An issue was discovered in Percona PMM before 3.7.

    CriticalCVSS 9.9Proof of conceptEPSS 0%

    percona · monitoring and managementApr 2, 2026

  • A flaw was found in the mysql-wsrep component of mariadb.

    CriticalCVSS 9.0No exploitEPSS 6%

    mariadb · mariadbMay 27, 2021

  • sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x bef

    HighCVSS 8.8No exploitEPSS 3%

    mariadb · mariadbJan 25, 2018

  • CVE-2014-2029
    33Monitor

    The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informa

    HighCVSS 8.1No exploitEPSS 2%

    percona · toolkitSep 28, 2017

  • An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.

    HighCVSS 8.1No exploitEPSS 2%

    percona · xtradb clusterApr 27, 2020

  • CVE-2020-7920
    31Monitor

    pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.

    HighCVSS 7.5No exploitEPSS 2%

    percona · monitoring and managementFeb 6, 2020

  • In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected c

    HighCVSS 7.8No exploitEPSS 0%

    percona · xtrabackupJun 6, 2023

  • An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL que

    HighCVSS 7.5No exploitEPSS 1%

    percona · percona serverAug 2, 2022

  • CVE-2016-6663
    29Monitor

    Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x

    HighCVSS 7.0Proof of conceptEPSS 4%

    oracle · mysqlDec 13, 2016

  • CVE-2016-6664
    29Monitor

    mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.

    HighCVSS 7.0Proof of conceptEPSS 3%

    oracle · mysqlDec 13, 2016

  • Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.

    MediumCVSS 6.5No exploitEPSS 1%

    percona · xtrabackupApr 27, 2020

  • Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.

    MediumCVSS 6.5No exploitEPSS 1%

    percona · xtrabackupJun 2, 2022

  • CVE-2015-1027
    23Monitor

    The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks

    MediumCVSS 5.9No exploitEPSS 1%

    percona · toolkitSep 28, 2017

  • CVE-2016-6225
    23Monitor

    xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which

    MediumCVSS 5.9No exploitEPSS 1%

    percona · xtrabackupMar 23, 2017

  • CVE-2024-7701
    20Monitor

    Misuse of SHA256 to create an encryption key

    MediumCVSS 5.1No exploitEPSS 0%

    percona · toolkitDec 15, 2024

  • Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat c

    LowCVSS 2.1No exploitEPSS 0%

    percona · xtrabackupDec 13, 2013