Skip to main content

Vendor archive

mysql CVEs

Beta · best-effort

112 CVEs tagged to vendor mysql7 Critical, 11 High, 75 Medium, 19 Low, 0 Unrated.

CVE-2009-4028

Published Nov 30, 2009

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 ce…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4019

Published Nov 30, 2009

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) pre…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7247

Published Nov 30, 2009

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2942

Published Oct 22, 2009

The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers to leverage escaping issues involving mu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2446

Published Jul 13, 2009

Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0819

Published Mar 5, 2009

sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a sc…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4456

Published Oct 6, 2008

Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3963

Published Sep 11, 2008

MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6313

Published Feb 18, 2008

MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6303

Published Dec 10, 2007

MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated use…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6304

Published Dec 10, 2007

The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5925

Published Nov 10, 2007

The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (da…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3780

Published Jul 15, 2007

MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3781

Published Jul 15, 2007

MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to o…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3782

Published Jul 15, 2007

MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-2692

Published May 16, 2007

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routin…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2693

Published May 16, 2007

MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-1420

Published Mar 12, 2007

MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-7232

Published Dec 31, 2006

sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMA…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4305

Published Aug 30, 2006

Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 51-75 of 112 CVEsPage 3 of 5