Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-16536 Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3. Clickhouse 19.14.3.3+ Fix from $1,9502025-05-21 HIGH 7.5 CVE-2024-41436 ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. Clickhouse No fix yet Fix from $1,9502024-09-03 HIGH 8.8 CVE-2024-23689 Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-clien… Java Libraries 0.4.6+ Fix from $1,9502024-01-19 HIGH 7.5 CVE-2023-48704 ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer ov… Clickhouse 23.3.18.15 / 23.8.8.20+ Fix from $1,9502023-12-22 HIGH 7.5 CVE-2023-48298 ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerabil… Clickhouse after 23.10.4.25 Fix from $1,9502023-12-21 CRITICAL 9.8 CVE-2023-47118 ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer o… Clickhouse 23.3.16.7 / 23.8.6.16+ Fix from $2,3002023-12-20 HIGH 7.5 CVE-2022-44010 An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on po… Clickhouse 22.3.12.19 / 22.6.6.16+ Fix from $1,9502023-11-23 MEDIUM 6.5 CVE-2022-44011 An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow an… Clickhouse 22.3.12.19 / 22.6.6.16+ Fix from $1,6002023-11-23 MEDIUM 6.5 CVE-2021-42389 Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo op… Clickhouse 21.10.2.15+ Fix from $1,6002022-03-14 MEDIUM 6.5 CVE-2021-42390 Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a mod… Clickhouse 21.10.2.15+ Fix from $1,6002022-03-14 MEDIUM 6.5 CVE-2021-42391 Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo … Clickhouse 21.10.2.15+ Fix from $1,6002022-03-14 CRITICAL 9.8 CVE-2019-16535 In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or Do… Clickhouse 19.14+ Fix from $2,3002019-12-30 MEDIUM 6.5 CVE-2019-15024 In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the … Clickhouse 19.14.3+ Fix from $1,6002019-12-30 MEDIUM 5.3 CVE-2019-18657 ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. Clickhouse 19.13.5.44+ Fix from $1,6002019-10-31 CRITICAL 9.8 CVE-2018-14670 Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database. Clickhouse 1.1.54131+ Fix from $2,3002019-08-15 CRITICAL 9.8 CVE-2018-14671 In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerabili… Clickhouse 18.10.3+ Fix from $2,3002019-08-15 HIGH 8.8 CVE-2018-14668 In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cr… Clickhouse 1.1.54388+ Fix from $1,9502019-08-15 HIGH 7.5 CVE-2018-14669 ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arb… Clickhouse 1.1.54390+ Fix from $1,9502019-08-15 MEDIUM 5.3 CVE-2018-14672 In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. Clickhouse 18.12.13+ Fix from $1,6002019-08-15