mysql records
112 published records for vendor mysql.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 2.7%
- Pre-auth RCE
- 11
- With a fix record
- 75.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-399 Resource Management Errors7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-20 Improper Input Validation4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-134 Use of Externally-Controlled Format String3
The weakness classes this vendor ships most often: where to look.
CWEAll records
112 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2006-4305Weaponized | Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connectmysql · maxdb | Critical10.0 | — | 71.7% | Aug 29, 2006 |
61This week | CVE-2004-0627Proof of concept | The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrmysql · mysql | Critical10.0 | — | 69.6% | Dec 6, 2004 |
61This week | CVE-2005-0684Weaponized | Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTPmysql · maxdb | Critical10.0 | — | 68.5% | Apr 25, 2005 |
60This week | CVE-2003-0780Proof of concept | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privilmysql · mysql | Critical9.0 | — | 78.4% | Sep 22, 2003 |
57Plan | CVE-2008-0226Weaponized | Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitryassl · yassl · CWE-119 | High7.5 | — | 91.6% | Jan 10, 2008 |
42Plan | CVE-2004-0628No exploit | Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly mysql · mysql | Critical10.0 | — | 7.8% | Dec 6, 2004 |
41Plan | CVE-2004-1168No exploit | Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code mysql · maxdb | Critical10.0 | — | 4.6% | Jan 10, 2005 |
41Plan | CVE-2005-1274No exploit | Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers mysql · maxdb | Critical10.0 | — | 4.2% | Apr 26, 2005 |
38Monitor | CVE-2006-1518Proof of concept | Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary codemysql · mysql | Medium6.5 | — | 38.4% | May 5, 2006 |
37Monitor | CVE-2004-0835Proof of concept | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original tablemysql · mysql | High7.5 | — | 22.4% | Nov 3, 2004 |
37Monitor | CVE-2009-2446Proof of concept | Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 almysql · mysql · CWE-134 | High8.5 | — | 10.6% | Jul 13, 2009 |
32Monitor | CVE-2007-5969No exploit | MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4mysql · mysql server · CWE-264 | High7.1 | — | 14.3% | Dec 10, 2007 |
32Monitor | CVE-2012-0882No exploit | Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows mysql · mysql · CWE-119 | High7.5 | — | 5.3% | Dec 21, 2012 |
31Monitor | CVE-2006-1516Proof of concept | The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackermysql · mysql | Medium5.0 | — | 35.8% | May 5, 2006 |
31Monitor | CVE-2010-1850No exploit | Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELmysql · mysql · CWE-119 | Medium6.0 | — | 21.8% | Jun 7, 2010 |
31Monitor | CVE-2005-0111No exploit | Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long pasmysql · maxdb | High7.5 | — | 3.8% | Jan 13, 2005 |
31Monitor | CVE-2006-2753No exploit | SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQLmysql · mysql | High7.5 | — | 3.5% | Jun 1, 2006 |
31Monitor | CVE-2013-1492No exploit | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a differemysql · mysql · CWE-119 | High7.5 | — | 2.8% | Mar 28, 2013 |
31Monitor | CVE-2012-0553No exploit | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a differemysql · mysql · CWE-119 | High7.5 | — | 2.6% | Mar 28, 2013 |
31Monitor | CVE-2009-2942No exploit | The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers tmysql-ocaml · mysql-ocaml | High7.5 | — | 2.3% | Oct 22, 2009 |
31Monitor | CVE-2017-15945No exploit | The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera mariadb · mariadb · CWE-732 | High7.8 | — | 0.4% | Oct 27, 2017 |
30Monitor | CVE-2006-4227Proof of concept | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of tmysql · mysql · CWE-20 | Medium6.5 | — | 13.6% | Aug 18, 2006 |
29Monitor | CVE-2009-5026Proof of concept | The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which tmysql · mysql · CWE-89 | Medium6.8 | — | 7.8% | Aug 16, 2012 |
28Monitor | CVE-2009-4028No exploit | The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a mysql · mysql · CWE-20 | Medium6.8 | — | 1.8% | Nov 30, 2009 |
27Monitor | CVE-2010-1848No exploit | Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended tabmysql · mysql · CWE-22 | Medium6.5 | — | 3.1% | Jun 7, 2010 |
- CVE-2006-430562This week
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connect
CriticalCVSS 10.0WeaponizedEPSS 72%mysql · maxdbAug 29, 2006
- CVE-2004-062761This week
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scr
CriticalCVSS 10.0Proof of conceptEPSS 70%mysql · mysqlDec 6, 2004
- CVE-2005-068461This week
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP
CriticalCVSS 10.0WeaponizedEPSS 69%mysql · maxdbApr 25, 2005
- CVE-2003-078060This week
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privil
CriticalCVSS 9.0Proof of conceptEPSS 78%mysql · mysqlSep 22, 2003
- CVE-2008-022657Plan
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitr
HighCVSS 7.5WeaponizedEPSS 92%yassl · yasslJan 10, 2008
- CVE-2004-062842Plan
Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly
CriticalCVSS 10.0No exploitEPSS 8%mysql · mysqlDec 6, 2004
- CVE-2004-116841Plan
Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code
CriticalCVSS 10.0No exploitEPSS 5%mysql · maxdbJan 10, 2005
- CVE-2005-127441Plan
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers
CriticalCVSS 10.0No exploitEPSS 4%mysql · maxdbApr 26, 2005
- CVE-2006-151838Monitor
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code
MediumCVSS 6.5Proof of conceptEPSS 38%mysql · mysqlMay 5, 2006
- CVE-2004-083537Monitor
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table
HighCVSS 7.5Proof of conceptEPSS 22%mysql · mysqlNov 3, 2004
- CVE-2009-244637Monitor
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 al
HighCVSS 8.5Proof of conceptEPSS 11%mysql · mysqlJul 13, 2009
- CVE-2007-596932Monitor
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4
HighCVSS 7.1No exploitEPSS 14%mysql · mysql serverDec 10, 2007
- CVE-2012-088232Monitor
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows
HighCVSS 7.5No exploitEPSS 5%mysql · mysqlDec 21, 2012
- CVE-2006-151631Monitor
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attacker
MediumCVSS 5.0Proof of conceptEPSS 36%mysql · mysqlMay 5, 2006
- CVE-2010-185031Monitor
Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIEL
MediumCVSS 6.0No exploitEPSS 22%mysql · mysqlJun 7, 2010
- CVE-2005-011131Monitor
Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long pas
HighCVSS 7.5No exploitEPSS 4%mysql · maxdbJan 13, 2005
- CVE-2006-275331Monitor
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL
HighCVSS 7.5No exploitEPSS 4%mysql · mysqlJun 1, 2006
- CVE-2013-149231Monitor
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a differe
HighCVSS 7.5No exploitEPSS 3%mysql · mysqlMar 28, 2013
- CVE-2012-055331Monitor
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a differe
HighCVSS 7.5No exploitEPSS 3%mysql · mysqlMar 28, 2013
- CVE-2009-294231Monitor
The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers t
HighCVSS 7.5No exploitEPSS 2%mysql-ocaml · mysql-ocamlOct 22, 2009
- CVE-2017-1594531Monitor
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera
HighCVSS 7.8No exploitEPSS 0%mariadb · mariadbOct 27, 2017
- CVE-2006-422730Monitor
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of t
MediumCVSS 6.5Proof of conceptEPSS 14%mysql · mysqlAug 18, 2006
- CVE-2009-502629Monitor
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which t
MediumCVSS 6.8Proof of conceptEPSS 8%mysql · mysqlAug 16, 2012
- CVE-2009-402828Monitor
The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a
MediumCVSS 6.8No exploitEPSS 2%mysql · mysqlNov 30, 2009
- CVE-2010-184827Monitor
Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended tab
MediumCVSS 6.5No exploitEPSS 3%mysql · mysqlJun 7, 2010