Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MySQL HIGH 7.5
CVE-2012-0553

Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulner…

Mitigation only
Fix from $1,950 2013-03-28
MySQL HIGH 7.5
CVE-2013-1492

Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulner…

Mitigation only
Fix from $1,950 2013-03-28
MySQL MEDIUM 6.8
CVE-2009-5026EPSS 8%

The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave …

No fix yet
Fix from $1,600 2012-08-17
MySQL MEDIUM 5.5
CVE-2012-0113

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality a…

No fix yet
Fix from $1,600 2012-01-18
MySQL MEDIUM 5.0
CVE-2011-2262

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote attackers to affect availability via unknown ve…

Mitigation only
Fix from $1,600 2012-01-18
MySQL MEDIUM 5.0
CVE-2010-3833

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a de…

Patch available
Fix from $1,600 2011-01-14
MySQL MEDIUM 6.5
CVE-2010-1848

Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants…

Mitigation only
Fix from $1,600 2010-06-08
MySQL MEDIUM 6.0
CVE-2010-1850EPSS 22%

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST co…

Mitigation only
Fix from $1,600 2010-06-08
MySQL MEDIUM 5.0
CVE-2010-1849

The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,600 2010-06-08
MySQL MEDIUM 5.0
CVE-2010-1621

The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which all…

Fix: after 5.1.45
Fix from $1,600 2010-05-14
MySQL MEDIUM 6.8
CVE-2009-4028

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of …

Fix: after 5.0.87
Fix from $1,600 2009-11-30
MySQL MEDIUM 6.0
CVE-2008-7247

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to …

No fix yet
Fix from $1,600 2009-11-30
MySQL HIGH 8.5
CVE-2009-2446EPSS 11%

Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remot…

Patch available
Fix from $1,950 2009-07-13
Mysql Community Server MEDIUM 6.5
CVE-2007-6313

MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized user…

Mitigation only
Fix from $1,600 2008-02-18
MySQL HIGH 7.5
CVE-2008-0226EPSS 92%

Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code …

Fix: after 1.7.5
Fix from $1,950 2008-01-10
MySQL MEDIUM 5.0
CVE-2007-6304

The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, a…

No fix yet
Fix from $1,600 2007-12-10
Mysql Server HIGH 7.1
CVE-2007-5969EPSS 14%

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a …

Fix: after 5.0.50
Fix from $1,950 2007-12-10
Community Server MEDIUM 5.0
CVE-2007-3780EPSS 14%

MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the conne…

Fix: after 5.0.41
Fix from $1,600 2007-07-15
MySQL MEDIUM 6.0
CVE-2007-2692

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL …

Mitigation only
Fix from $1,600 2007-05-16
Maxdb HIGH 10.0
CVE-2006-4305EPSS 71%

Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a…

Fix: after 7.6.00.22
Fix from $1,950 2006-08-30
MySQL MEDIUM 6.5
CVE-2006-4227EPSS 12%

MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routin…

No fix yet
Fix from $1,600 2006-08-18
MySQL HIGH 7.5
CVE-2006-2753

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands…

Patch available
Fix from $1,950 2006-06-01
MySQL MEDIUM 6.5
CVE-2006-1518EPSS 38%

Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via craf…

Patch available
Fix from $1,600 2006-05-05
MySQL MEDIUM 5.0
CVE-2006-1516EPSS 36%

The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read…

Patch available
Fix from $1,600 2006-05-05
MySQL MEDIUM 5.0
CVE-2006-1517

sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a CO…

Patch available
Fix from $1,600 2006-05-05
Eventum MEDIUM 6.4
CVE-2005-2468

Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorr…

Patch available
Fix from $1,600 2005-12-31
Eventum MEDIUM 5.8
CVE-2005-2467

Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML …

Patch available
Fix from $1,600 2005-12-31
MySQL MEDIUM 5.0
CVE-2005-2573

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, …

Patch available
Fix from $1,600 2005-08-16
Maxdb MEDIUM 5.0
CVE-2005-0083

MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application …

Patch available
Fix from $1,600 2005-05-02
Maxdb HIGH 10.0
CVE-2005-1274

Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execut…

Fix: after 7.5.00.23
Fix from $1,950 2005-04-26