Записи Percona
21 опубликованных записей вендора percona.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 57,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-310 Cryptographic Issues1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2016-6662Proof of concept | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Критическая9,8 | — | 67,7 % | 20 сент. 2016 г. |
40В плане | CVE-2021-27928Proof of concept | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.mariadb · mariadb · CWE-94 | Высокая7,2 | — | 38,4 % | 18 мар. 2021 г. |
40В плане | CVE-2019-12301Эксплойта нет | The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank percona · percona server | Критическая9,8 | — | 2,0 % | 23 мая 2019 г. |
39Наблюдать | CVE-2020-26542Эксплойта нет | An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in percona · percona server · CWE-287 | Критическая9,8 | — | 1,5 % | 9 нояб. 2020 г. |
39Наблюдать | CVE-2023-34409Эксплойта нет | In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalizepercona · monitoring and management · CWE-22 | Критическая9,8 | — | 1,3 % | 6 июн. 2023 г. |
39Наблюдать | CVE-2026-25212Proof of concept | An issue was discovered in Percona PMM before 3.7.percona · monitoring and management · CWE-250 | Критическая9,9 | — | 0,3 % | 2 апр. 2026 г. |
38Наблюдать | CVE-2020-15180Эксплойта нет | A flaw was found in the mysql-wsrep component of mariadb.mariadb · mariadb · CWE-20 | Критическая9,0 | — | 5,5 % | 27 мая 2021 г. |
36Наблюдать | CVE-2017-15365Эксплойта нет | sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x befmariadb · mariadb | Высокая8,8 | — | 3,3 % | 25 янв. 2018 г. |
33Наблюдать | CVE-2014-2029Эксплойта нет | The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informapercona · toolkit · CWE-200 | Высокая8,1 | — | 2,0 % | 28 сент. 2017 г. |
32Наблюдать | CVE-2020-10996Эксплойта нет | An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.percona · xtradb cluster · CWE-798 | Высокая8,1 | — | 1,5 % | 27 апр. 2020 г. |
31Наблюдать | CVE-2020-7920Эксплойта нет | pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.percona · monitoring and management · CWE-835 | Высокая7,5 | — | 2,1 % | 6 февр. 2020 г. |
31Наблюдать | CVE-2022-25834Эксплойта нет | In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected cpercona · xtrabackup · CWE-77 | Высокая7,8 | — | 0,5 % | 6 июн. 2023 г. |
30Наблюдать | CVE-2022-34968Эксплойта нет | An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL quepercona · percona server · CWE-89 | Высокая7,5 | — | 1,0 % | 2 авг. 2022 г. |
29Наблюдать | CVE-2016-6663Proof of concept | Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x oracle · mysql · CWE-362 | Высокая7,0 | — | 4,3 % | 13 дек. 2016 г. |
29Наблюдать | CVE-2016-6664Proof of concept | mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.oracle · mysql · CWE-59 | Высокая7,0 | — | 3,0 % | 13 дек. 2016 г. |
26Наблюдать | CVE-2020-10997Эксплойта нет | Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.percona · xtrabackup · CWE-200 | Средняя6,5 | — | 1,0 % | 27 апр. 2020 г. |
26Наблюдать | CVE-2022-26944Эксплойта нет | Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.percona · xtrabackup | Средняя6,5 | — | 0,9 % | 2 июн. 2022 г. |
23Наблюдать | CVE-2015-1027Эксплойта нет | The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attackspercona · toolkit · CWE-200 | Средняя5,9 | — | 1,2 % | 28 сент. 2017 г. |
23Наблюдать | CVE-2016-6225Эксплойта нет | xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, whichpercona · xtrabackup · CWE-326 | Средняя5,9 | — | 1,1 % | 23 мар. 2017 г. |
20Наблюдать | CVE-2024-7701Эксплойта нет | Misuse of SHA256 to create an encryption keypercona · toolkit · CWE-916 | Средняя5,1 | — | 0,2 % | 15 дек. 2024 г. |
8Наблюдать | CVE-2013-6394Эксплойта нет | Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cpercona · xtrabackup · CWE-310 | Низкая2,1 | — | 0,4 % | 13 дек. 2013 г. |
- CVE-2016-666259В плане
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
КритическаяCVSS 9,8Proof of conceptEPSS 68 %oracle · mysql20 сент. 2016 г.
- CVE-2021-2792840В плане
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.
ВысокаяCVSS 7,2Proof of conceptEPSS 38 %mariadb · mariadb18 мар. 2021 г.
- CVE-2019-1230140В плане
The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %percona · percona server23 мая 2019 г.
- CVE-2020-2654239Наблюдать
An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %percona · percona server9 нояб. 2020 г.
- CVE-2023-3440939Наблюдать
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %percona · monitoring and management6 июн. 2023 г.
- CVE-2026-2521239Наблюдать
An issue was discovered in Percona PMM before 3.7.
КритическаяCVSS 9,9Proof of conceptEPSS 0 %percona · monitoring and management2 апр. 2026 г.
- CVE-2020-1518038Наблюдать
A flaw was found in the mysql-wsrep component of mariadb.
КритическаяCVSS 9,0Эксплойта нетEPSS 6 %mariadb · mariadb27 мая 2021 г.
- CVE-2017-1536536Наблюдать
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x bef
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mariadb · mariadb25 янв. 2018 г.
- CVE-2014-202933Наблюдать
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive informa
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %percona · toolkit28 сент. 2017 г.
- CVE-2020-1099632Наблюдать
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %percona · xtradb cluster27 апр. 2020 г.
- CVE-2020-792031Наблюдать
pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %percona · monitoring and management6 февр. 2020 г.
- CVE-2022-2583431Наблюдать
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected c
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %percona · xtrabackup6 июн. 2023 г.
- CVE-2022-3496830Наблюдать
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL que
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %percona · percona server2 авг. 2022 г.
- CVE-2016-666329Наблюдать
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x
ВысокаяCVSS 7,0Proof of conceptEPSS 4 %oracle · mysql13 дек. 2016 г.
- CVE-2016-666429Наблюдать
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.
ВысокаяCVSS 7,0Proof of conceptEPSS 3 %oracle · mysql13 дек. 2016 г.
- CVE-2020-1099726Наблюдать
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %percona · xtrabackup27 апр. 2020 г.
- CVE-2022-2694426Наблюдать
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %percona · xtrabackup2 июн. 2022 г.
- CVE-2015-102723Наблюдать
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks
СредняяCVSS 5,9Эксплойта нетEPSS 1 %percona · toolkit28 сент. 2017 г.
- CVE-2016-622523Наблюдать
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which
СредняяCVSS 5,9Эксплойта нетEPSS 1 %percona · xtrabackup23 мар. 2017 г.
- CVE-2024-770120Наблюдать
Misuse of SHA256 to create an encryption key
СредняяCVSS 5,1Эксплойта нетEPSS 0 %percona · toolkit15 дек. 2024 г.
- CVE-2013-63948Наблюдать
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat c
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %percona · xtrabackup13 дек. 2013 г.