Записи mysql
112 опубликованных записей вендора mysql.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 2,7 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 75,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-399 Resource Management Errors7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-20 Improper Input Validation4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-134 Use of Externally-Controlled Format String3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
112 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2006-4305Готовый эксплойт | Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connectmysql · maxdb | Критическая10,0 | — | 71,7 % | 29 авг. 2006 г. |
61На этой неделе | CVE-2004-0627Proof of concept | The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrmysql · mysql | Критическая10,0 | — | 69,6 % | 6 дек. 2004 г. |
61На этой неделе | CVE-2005-0684Готовый эксплойт | Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTPmysql · maxdb | Критическая10,0 | — | 68,5 % | 25 апр. 2005 г. |
60На этой неделе | CVE-2003-0780Proof of concept | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privilmysql · mysql | Критическая9,0 | — | 78,4 % | 22 сент. 2003 г. |
57В плане | CVE-2008-0226Готовый эксплойт | Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitryassl · yassl · CWE-119 | Высокая7,5 | — | 91,6 % | 10 янв. 2008 г. |
42В плане | CVE-2004-0628Эксплойта нет | Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly mysql · mysql | Критическая10,0 | — | 7,8 % | 6 дек. 2004 г. |
41В плане | CVE-2004-1168Эксплойта нет | Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code mysql · maxdb | Критическая10,0 | — | 4,6 % | 10 янв. 2005 г. |
41В плане | CVE-2005-1274Эксплойта нет | Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers mysql · maxdb | Критическая10,0 | — | 4,2 % | 26 апр. 2005 г. |
38Наблюдать | CVE-2006-1518Proof of concept | Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary codemysql · mysql | Средняя6,5 | — | 38,4 % | 5 мая 2006 г. |
37Наблюдать | CVE-2004-0835Proof of concept | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original tablemysql · mysql | Высокая7,5 | — | 22,4 % | 3 нояб. 2004 г. |
37Наблюдать | CVE-2009-2446Proof of concept | Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 almysql · mysql · CWE-134 | Высокая8,5 | — | 10,6 % | 13 июл. 2009 г. |
32Наблюдать | CVE-2007-5969Эксплойта нет | MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4mysql · mysql server · CWE-264 | Высокая7,1 | — | 14,3 % | 10 дек. 2007 г. |
32Наблюдать | CVE-2012-0882Эксплойта нет | Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows mysql · mysql · CWE-119 | Высокая7,5 | — | 5,3 % | 21 дек. 2012 г. |
31Наблюдать | CVE-2006-1516Proof of concept | The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackermysql · mysql | Средняя5,0 | — | 35,8 % | 5 мая 2006 г. |
31Наблюдать | CVE-2010-1850Эксплойта нет | Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELmysql · mysql · CWE-119 | Средняя6,0 | — | 21,8 % | 7 июн. 2010 г. |
31Наблюдать | CVE-2005-0111Эксплойта нет | Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long pasmysql · maxdb | Высокая7,5 | — | 3,8 % | 13 янв. 2005 г. |
31Наблюдать | CVE-2006-2753Эксплойта нет | SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQLmysql · mysql | Высокая7,5 | — | 3,5 % | 1 июн. 2006 г. |
31Наблюдать | CVE-2013-1492Эксплойта нет | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a differemysql · mysql · CWE-119 | Высокая7,5 | — | 2,8 % | 28 мар. 2013 г. |
31Наблюдать | CVE-2012-0553Эксплойта нет | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a differemysql · mysql · CWE-119 | Высокая7,5 | — | 2,6 % | 28 мар. 2013 г. |
31Наблюдать | CVE-2009-2942Эксплойта нет | The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers tmysql-ocaml · mysql-ocaml | Высокая7,5 | — | 2,3 % | 22 окт. 2009 г. |
31Наблюдать | CVE-2017-15945Эксплойта нет | The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera mariadb · mariadb · CWE-732 | Высокая7,8 | — | 0,4 % | 27 окт. 2017 г. |
30Наблюдать | CVE-2006-4227Proof of concept | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of tmysql · mysql · CWE-20 | Средняя6,5 | — | 13,6 % | 18 авг. 2006 г. |
29Наблюдать | CVE-2009-5026Proof of concept | The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which tmysql · mysql · CWE-89 | Средняя6,8 | — | 7,8 % | 16 авг. 2012 г. |
28Наблюдать | CVE-2009-4028Эксплойта нет | The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a mysql · mysql · CWE-20 | Средняя6,8 | — | 1,8 % | 30 нояб. 2009 г. |
27Наблюдать | CVE-2010-1848Эксплойта нет | Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended tabmysql · mysql · CWE-22 | Средняя6,5 | — | 3,1 % | 7 июн. 2010 г. |
- CVE-2006-430562На этой неделе
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connect
КритическаяCVSS 10,0Готовый эксплойтEPSS 72 %mysql · maxdb29 авг. 2006 г.
- CVE-2004-062761На этой неделе
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scr
КритическаяCVSS 10,0Proof of conceptEPSS 70 %mysql · mysql6 дек. 2004 г.
- CVE-2005-068461На этой неделе
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP
КритическаяCVSS 10,0Готовый эксплойтEPSS 69 %mysql · maxdb25 апр. 2005 г.
- CVE-2003-078060На этой неделе
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privil
КритическаяCVSS 9,0Proof of conceptEPSS 78 %mysql · mysql22 сент. 2003 г.
- CVE-2008-022657В плане
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitr
ВысокаяCVSS 7,5Готовый эксплойтEPSS 92 %yassl · yassl10 янв. 2008 г.
- CVE-2004-062842В плане
Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %mysql · mysql6 дек. 2004 г.
- CVE-2004-116841В плане
Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %mysql · maxdb10 янв. 2005 г.
- CVE-2005-127441В плане
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %mysql · maxdb26 апр. 2005 г.
- CVE-2006-151838Наблюдать
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code
СредняяCVSS 6,5Proof of conceptEPSS 38 %mysql · mysql5 мая 2006 г.
- CVE-2004-083537Наблюдать
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table
ВысокаяCVSS 7,5Proof of conceptEPSS 22 %mysql · mysql3 нояб. 2004 г.
- CVE-2009-244637Наблюдать
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 al
ВысокаяCVSS 8,5Proof of conceptEPSS 11 %mysql · mysql13 июл. 2009 г.
- CVE-2007-596932Наблюдать
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4
ВысокаяCVSS 7,1Эксплойта нетEPSS 14 %mysql · mysql server10 дек. 2007 г.
- CVE-2012-088232Наблюдать
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %mysql · mysql21 дек. 2012 г.
- CVE-2006-151631Наблюдать
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attacker
СредняяCVSS 5,0Proof of conceptEPSS 36 %mysql · mysql5 мая 2006 г.
- CVE-2010-185031Наблюдать
Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIEL
СредняяCVSS 6,0Эксплойта нетEPSS 22 %mysql · mysql7 июн. 2010 г.
- CVE-2005-011131Наблюдать
Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long pas
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mysql · maxdb13 янв. 2005 г.
- CVE-2006-275331Наблюдать
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mysql · mysql1 июн. 2006 г.
- CVE-2013-149231Наблюдать
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a differe
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mysql · mysql28 мар. 2013 г.
- CVE-2012-055331Наблюдать
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a differe
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mysql · mysql28 мар. 2013 г.
- CVE-2009-294231Наблюдать
The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mysql-ocaml · mysql-ocaml22 окт. 2009 г.
- CVE-2017-1594531Наблюдать
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mariadb · mariadb27 окт. 2017 г.
- CVE-2006-422730Наблюдать
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of t
СредняяCVSS 6,5Proof of conceptEPSS 14 %mysql · mysql18 авг. 2006 г.
- CVE-2009-502629Наблюдать
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which t
СредняяCVSS 6,8Proof of conceptEPSS 8 %mysql · mysql16 авг. 2012 г.
- CVE-2009-402828Наблюдать
The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a
СредняяCVSS 6,8Эксплойта нетEPSS 2 %mysql · mysql30 нояб. 2009 г.
- CVE-2010-184827Наблюдать
Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended tab
СредняяCVSS 6,5Эксплойта нетEPSS 3 %mysql · mysql7 июн. 2010 г.