MariaDB kayıtları
mariadb üreticisine ait 419 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %1,2
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %92,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-416 Use After Free12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-667 Improper Locking5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-617 Reachable Assertion4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
419 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2016-6662Kavram kanıtı | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Kritik9,8 | — | %67,7 | 20 Eyl 2016 |
58Planlayın | CVE-2014-0224Silahlaştırılmış | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Yüksek7,4 | — | %95,3 | 5 Haz 2014 |
57Planlayın | CVE-2014-0195Silahlaştırılmış | The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properlopenssl · openssl · CWE-120 | Orta6,8 | — | %100,0 | 5 Haz 2014 |
52Planlayın | CVE-2022-0778Kavram kanıtı | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Yüksek7,5 | — | %73,2 | 15 Mar 2022 |
51Planlayın | CVE-2009-4484Silahlaştırılmış | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqoracle · mysql · CWE-787 | Yüksek7,5 | — | %69,6 | 30 Ara 2009 |
49Planlayın | CVE-2012-2122Silahlaştırılmış | sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x befooracle · mysql · CWE-287 | Orta5,1 | — | %96,5 | 26 Haz 2012 |
46Planlayın | CVE-2018-25032Kavram kanıtı | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.zlib · zlib · CWE-787 | Yüksek7,5 | — | %51,7 | 25 Mar 2022 |
43Planlayın | CVE-2014-0221Kavram kanıtı | The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote aopenssl · openssl | Orta4,3 | — | %87,9 | 5 Haz 2014 |
43Planlayın | CVE-2014-3470İstismar yok | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anoopenssl · openssl · CWE-476 | Orta4,3 | — | %85,8 | 5 Haz 2014 |
41Planlayın | CVE-2016-9843İstismar yok | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving bigzlib · zlib | Kritik9,8 | — | %5,8 | 23 May 2017 |
41Planlayın | CVE-2012-2750İstismar yok | Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533.oracle · mysql | Kritik10,0 | — | %3,6 | 16 Ağu 2012 |
40Planlayın | CVE-2021-27928Kavram kanıtı | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.mariadb · mariadb · CWE-94 | Yüksek7,2 | — | %38,4 | 18 Mar 2021 |
40Planlayın | CVE-2023-26785İstismar yok | MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "cremariadb · mariadb · CWE-94 | Kritik9,8 | — | %2,2 | 17 Eki 2024 |
40Planlayın | CVE-2026-49261İstismar yok | MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`mariadb · mariadb · CWE-78 | Kritik9,8 | — | %1,7 | 11 Haz 2026 |
39İzleyin | CVE-2026-32710Kavram kanıtı | Heap-based Buffer Overflow in MariaDBmariadb · mariadb · CWE-122 | Kritik9,9 | — | %0,8 | 20 Mar 2026 |
38İzleyin | CVE-2020-15180İstismar yok | A flaw was found in the mysql-wsrep component of mariadb.mariadb · mariadb · CWE-20 | Kritik9,0 | — | %5,5 | 27 May 2021 |
38İzleyin | CVE-2012-3163İstismar yok | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticaoracle · mysql | Kritik9,0 | — | %5,1 | 16 Eki 2012 |
36İzleyin | CVE-2017-15365İstismar yok | sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x befmariadb · mariadb | Yüksek8,8 | — | %3,3 | 25 Oca 2018 |
36İzleyin | CVE-2020-13249İstismar yok | libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server.mariadb · connector\/c | Yüksek8,8 | — | %2,4 | 20 May 2020 |
33İzleyin | CVE-2012-5613Silahlaştırılmış | MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to umariadb · mariadb · CWE-16 | Orta6,0 | — | %31,7 | 3 Ara 2012 |
33İzleyin | CVE-2012-5611Kavram kanıtı | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions oracle · mysql · CWE-119 | Orta6,5 | — | %24,0 | 3 Ara 2012 |
33İzleyin | CVE-2015-0411İstismar yok | Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentialioracle · communications policy management | Yüksek7,5 | — | %9,6 | 21 Oca 2015 |
32İzleyin | CVE-2012-5612Kavram kanıtı | Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allowsmariadb · mariadb · CWE-787 | Orta6,5 | — | %20,8 | 3 Ara 2012 |
32İzleyin | CVE-2014-0001İstismar yok | Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crmariadb · mariadb · CWE-119 | Yüksek7,5 | — | %6,4 | 31 Oca 2014 |
32İzleyin | CVE-2014-6491İstismar yok | Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentialityoracle · mysql | Yüksek7,5 | — | %5,7 | 15 Eki 2014 |
- CVE-2016-666259Planlayın
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
KritikCVSS 9,8Kavram kanıtıEPSS %68oracle · mysql20 Eyl 2016
- CVE-2014-022458Planlayın
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
YüksekCVSS 7,4SilahlaştırılmışEPSS %95openssl · openssl5 Haz 2014
- CVE-2014-019557Planlayın
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properl
OrtaCVSS 6,8SilahlaştırılmışEPSS %100openssl · openssl5 Haz 2014
- CVE-2022-077852Planlayın
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
YüksekCVSS 7,5Kavram kanıtıEPSS %73openssl · openssl15 Mar 2022
- CVE-2009-448451Planlayın
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysq
YüksekCVSS 7,5SilahlaştırılmışEPSS %70oracle · mysql30 Ara 2009
- CVE-2012-212249Planlayın
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x befo
OrtaCVSS 5,1SilahlaştırılmışEPSS %97oracle · mysql26 Haz 2012
- CVE-2018-2503246Planlayın
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
YüksekCVSS 7,5Kavram kanıtıEPSS %52zlib · zlib25 Mar 2022
- CVE-2014-022143Planlayın
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote a
OrtaCVSS 4,3Kavram kanıtıEPSS %88openssl · openssl5 Haz 2014
- CVE-2014-347043Planlayın
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an ano
OrtaCVSS 4,3İstismar yokEPSS %86openssl · openssl5 Haz 2014
- CVE-2016-984341Planlayın
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big
KritikCVSS 9,8İstismar yokEPSS %6zlib · zlib23 May 2017
- CVE-2012-275041Planlayın
Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533.
KritikCVSS 10,0İstismar yokEPSS %4oracle · mysql16 Ağu 2012
- CVE-2021-2792840Planlayın
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.
YüksekCVSS 7,2Kavram kanıtıEPSS %38mariadb · mariadb18 Mar 2021
- CVE-2023-2678540Planlayın
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "cre
KritikCVSS 9,8İstismar yokEPSS %2mariadb · mariadb17 Eki 2024
- CVE-2026-4926140Planlayın
MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
KritikCVSS 9,8İstismar yokEPSS %2mariadb · mariadb11 Haz 2026
- CVE-2026-3271039İzleyin
Heap-based Buffer Overflow in MariaDB
KritikCVSS 9,9Kavram kanıtıEPSS %1mariadb · mariadb20 Mar 2026
- CVE-2020-1518038İzleyin
A flaw was found in the mysql-wsrep component of mariadb.
KritikCVSS 9,0İstismar yokEPSS %6mariadb · mariadb27 May 2021
- CVE-2012-316338İzleyin
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authentica
KritikCVSS 9,0İstismar yokEPSS %5oracle · mysql16 Eki 2012
- CVE-2017-1536536İzleyin
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x bef
YüksekCVSS 8,8İstismar yokEPSS %3mariadb · mariadb25 Oca 2018
- CVE-2020-1324936İzleyin
libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server.
YüksekCVSS 8,8İstismar yokEPSS %2mariadb · connector\/c20 May 2020
- CVE-2012-561333İzleyin
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to u
OrtaCVSS 6,0SilahlaştırılmışEPSS %32mariadb · mariadb3 Ara 2012
- CVE-2012-561133İzleyin
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions
OrtaCVSS 6,5Kavram kanıtıEPSS %24oracle · mysql3 Ara 2012
- CVE-2015-041133İzleyin
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiali
YüksekCVSS 7,5İstismar yokEPSS %10oracle · communications policy management21 Oca 2015
- CVE-2012-561232İzleyin
Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows
OrtaCVSS 6,5Kavram kanıtıEPSS %21mariadb · mariadb3 Ara 2012
- CVE-2014-000132İzleyin
Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (cr
YüksekCVSS 7,5İstismar yokEPSS %6mariadb · mariadb31 Oca 2014
- CVE-2014-649132İzleyin
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality
YüksekCVSS 7,5İstismar yokEPSS %6oracle · mysql15 Eki 2014