Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Clickhouse HIGH 8.8
CVE-2019-16536

Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

Fix: 19.14.3.3+
Fix from $1,950 2025-05-21
Clickhouse HIGH 7.5
CVE-2024-41436

ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.

No fix yet
Fix from $1,950 2024-09-03
Java Libraries HIGH 8.8
CVE-2024-23689

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-clien…

Fix: 0.4.6+
Fix from $1,950 2024-01-19
Clickhouse HIGH 7.5
CVE-2023-48704

ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer ov…

Fix: 23.3.18.15 / 23.8.8.20+
Fix from $1,950 2023-12-22
Clickhouse HIGH 7.5
CVE-2023-48298

ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerabil…

Fix: after 23.10.4.25
Fix from $1,950 2023-12-21
Clickhouse CRITICAL 9.8
CVE-2023-47118

ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer o…

Fix: 23.3.16.7 / 23.8.6.16+
Fix from $2,300 2023-12-20
Clickhouse HIGH 7.5
CVE-2022-44010

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on po…

Fix: 22.3.12.19 / 22.6.6.16+
Fix from $1,950 2023-11-23
Clickhouse MEDIUM 6.5
CVE-2022-44011

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow an…

Fix: 22.3.12.19 / 22.6.6.16+
Fix from $1,600 2023-11-23
Clickhouse MEDIUM 6.5
CVE-2021-42389

Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo op…

Fix: 21.10.2.15+
Fix from $1,600 2022-03-14
Clickhouse MEDIUM 6.5
CVE-2021-42390

Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a mod…

Fix: 21.10.2.15+
Fix from $1,600 2022-03-14
Clickhouse MEDIUM 6.5
CVE-2021-42391

Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo …

Fix: 21.10.2.15+
Fix from $1,600 2022-03-14
Clickhouse CRITICAL 9.8
CVE-2019-16535

In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or Do…

Fix: 19.14+
Fix from $2,300 2019-12-30
Clickhouse MEDIUM 6.5
CVE-2019-15024

In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the …

Fix: 19.14.3+
Fix from $1,600 2019-12-30
Clickhouse MEDIUM 5.3
CVE-2019-18657

ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

Fix: 19.13.5.44+
Fix from $1,600 2019-10-31
Clickhouse CRITICAL 9.8
CVE-2018-14670

Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.

Fix: 1.1.54131+
Fix from $2,300 2019-08-15
Clickhouse CRITICAL 9.8
CVE-2018-14671

In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerabili…

Fix: 18.10.3+
Fix from $2,300 2019-08-15
Clickhouse HIGH 8.8
CVE-2018-14668

In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cr…

Fix: 1.1.54388+
Fix from $1,950 2019-08-15
Clickhouse HIGH 7.5
CVE-2018-14669

ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arb…

Fix: 1.1.54390+
Fix from $1,950 2019-08-15
Clickhouse MEDIUM 5.3
CVE-2018-14672

In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.

Fix: 18.12.13+
Fix from $1,600 2019-08-15