Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-16536
Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.
Clickhouse
19.14.3.3+
HIGH 7.5
CVE-2024-41436
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
Clickhouse
No fix yet
HIGH 8.8
CVE-2024-23689
Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-clien…
Java Libraries
0.4.6+
HIGH 7.5
CVE-2023-48704
ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer ov…
Clickhouse
23.3.18.15 / 23.8.8.20+
HIGH 7.5
CVE-2023-48298
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerabil…
Clickhouse
after 23.10.4.25
CRITICAL 9.8
CVE-2023-47118
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer o…
Clickhouse
23.3.16.7 / 23.8.6.16+
HIGH 7.5
CVE-2022-44010
An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on po…
Clickhouse
22.3.12.19 / 22.6.6.16+
MEDIUM 6.5
CVE-2022-44011
An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow an…
Clickhouse
22.3.12.19 / 22.6.6.16+
MEDIUM 6.5
CVE-2021-42389
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo op…
Clickhouse
21.10.2.15+
MEDIUM 6.5
CVE-2021-42390
Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a mod…
Clickhouse
21.10.2.15+
MEDIUM 6.5
CVE-2021-42391
Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo …
Clickhouse
21.10.2.15+
CRITICAL 9.8
CVE-2019-16535
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or Do…
Clickhouse
19.14+
MEDIUM 6.5
CVE-2019-15024
In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the …
Clickhouse
19.14.3+
MEDIUM 5.3
CVE-2019-18657
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
Clickhouse
19.13.5.44+
CRITICAL 9.8
CVE-2018-14670
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
Clickhouse
1.1.54131+
CRITICAL 9.8
CVE-2018-14671
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerabili…
Clickhouse
18.10.3+
HIGH 8.8
CVE-2018-14668
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cr…
Clickhouse
1.1.54388+
HIGH 7.5
CVE-2018-14669
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arb…
Clickhouse
1.1.54390+
MEDIUM 5.3
CVE-2018-14672
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
Clickhouse
18.12.13+