Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MariaDB MEDIUM 5.5
CVE-2021-46666

MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.

Fix: 10.2.39 / 10.3.30+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46667

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

Fix: 10.2.41 / 10.3.32+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46668

MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource …

Fix: 10.2.43 / 10.3.34+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46661

MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

Fix: 10.2.43 / 10.3.34+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46662

MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

Fix: 10.3.32 / 10.4.22+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46663

MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.

Fix: 10.2.43 / 10.3.34+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46664

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

Fix: 10.2.43 / 10.3.34+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46665

MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.

Fix: 10.2.43 / 10.3.34+
Fix from $1,600 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

Fix: 10.2.39 / 10.3.30+
Fix from $1,600 2022-01-29
MariaDB MEDIUM 5.5
CVE-2021-46658

save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquer…

Fix: 10.2.40 / 10.3.31+
Fix from $1,600 2022-01-29
MariaDB MEDIUM 5.5
CVE-2021-46659

MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

Fix: 10.2.42 / 10.3.33+
Fix from $1,600 2022-01-29
MariaDB CRITICAL 9.0
CVE-2020-15180EPSS 6%

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be e…

Fix: 5.6.49 / 5.6.49-28.42.2+
Fix from $2,300 2021-05-27
MariaDB HIGH 7.2
CVE-2021-27928EPSS 38%

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percon…

Fix: 10.2.37 / 10.3.28+
Fix from $1,950 2021-03-19
MariaDB HIGH 7.0
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to…

Fix: 10.1.48 / 10.2.35+
Fix from $1,950 2020-12-24
Connector\/c HIGH 8.8
CVE-2020-13249

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: alt…

Fix: 3.1.8+
Fix from $1,950 2020-05-20
MariaDB HIGH 7.8
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are perfor…

Fix: after 10.4.11
Fix from $1,950 2020-02-04
MariaDB HIGH 7.8
CVE-2015-2325

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bound…

Fix: 5.4.41 / 5.5.26+
Fix from $1,950 2020-01-14
MariaDB MEDIUM 5.5
CVE-2015-2326

The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bou…

Fix: 5.4.41 / 5.5.26+
Fix from $1,600 2020-01-14
MariaDB HIGH 7.5
CVE-2017-16046

`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Mitigation only
Fix from $1,950 2018-06-04
MariaDB HIGH 7.8
CVE-2017-15945

The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages …

Fix: 5.6.36 / 10.0.30+
Fix from $1,950 2017-10-27
MariaDB MEDIUM 5.5
CVE-2016-7440

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover…

Fix: 3.9.10 / 5.5.53+
Fix from $1,600 2016-12-13
MariaDB MEDIUM 6.5
CVE-2016-3521EPSS 6%

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.…

Fix: 5.5.50 / 10.0.26+
Fix from $1,600 2016-07-21
MariaDB MEDIUM 5.9
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5…

Fix: 5.5.47 / 10.0.23+
Fix from $1,600 2016-01-27
MariaDB MEDIUM 5.9
CVE-2015-7744EPSS 5%

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephe…

Fix: 3.6.8 / 5.5.46+
Fix from $1,600 2016-01-22
MariaDB MEDIUM 5.0
CVE-2014-8964EPSS 7%

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via…

Fix: 10.0.18+
Fix from $1,600 2014-12-16
MariaDB MEDIUM 6.5
CVE-2014-6555

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect confidentialit…

Fix: 5.5.40 / 10.0.15+
Fix from $1,600 2014-10-15
MariaDB HIGH 7.5
CVE-2014-6500EPSS 6%

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integ…

Fix: 5.5.40 / 10.0.15+
Fix from $1,950 2014-10-15
MariaDB MEDIUM 6.8
CVE-2014-6469

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability v…

Fix: 5.5.40 / 10.0.15+
Fix from $1,600 2014-10-15
MariaDB HIGH 7.5
CVE-2014-0001EPSS 6%

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and …

Fix: after 5.5.34
Fix from $1,950 2014-01-31
MariaDB MEDIUM 5.0
CVE-2013-1861EPSS 19%

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earli…

Fix: 5.5.32 / 10.0.4+
Fix from $1,600 2013-03-28