Skip to main content

Vendor archive

mysql CVEs

Beta · best-effort

112 CVEs tagged to vendor mysql7 Critical, 11 High, 75 Medium, 19 Low, 0 Unrated.

CVE-2012-0087

Published Jan 18, 2012

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different v…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0075

Published Jan 18, 2012

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect integrity via unknown vectors.

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2262

Published Jan 18, 2012

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote attackers to affect availability via unknown vectors.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-3840

Published Jan 14, 2011

The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling t…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3839

Published Jan 14, 2011

MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (infinite loop) via multiple invocations of a (1) prepared statement or…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3838

Published Jan 14, 2011

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATE…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3837

Published Jan 14, 2011

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a prepared statement that uses G…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3836

Published Jan 14, 2011

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors re…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3835

Published Jan 14, 2011

MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a log…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3834

Published Jan 14, 2011

Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vec…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3833

Published Jan 14, 2011

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3683

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a den…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3682

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ...…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3681

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and perform…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3680

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with nullable columns while using…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3679

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3678

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly spe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3677

Published Jan 11, 2011

Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3676

Published Jan 11, 2011

storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1850

Published Jun 8, 2010

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1849

Published Jun 8, 2010

The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumpt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1848

Published Jun 8, 2010

Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1626

Published May 21, 2010

MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a differe…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1621

Published May 14, 2010

The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which allows remote attackers to uninst…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4030

Published Nov 30, 2009

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 112 CVEsPage 2 of 5