Skip to main content

Vendor archive

mysql CVEs

Beta · best-effort

112 CVEs tagged to vendor mysql7 Critical, 11 High, 75 Medium, 19 Low, 0 Unrated.

CVE-2006-4380

Published Aug 28, 2006

MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4226

Published Aug 18, 2006

MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the da…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4227

Published Aug 18, 2006

MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remot…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4031

Published Aug 9, 2006

MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3469

Published Jul 21, 2006

Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a f…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3486

Published Jul 10, 2006

Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 mi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3081

Published Jun 19, 2006

mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2753

Published Jun 1, 2006

SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1516

Published May 5, 2006

The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a user…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1517

Published May 5, 2006

sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1518

Published May 5, 2006

Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets wit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0903

Published Feb 27, 2006

MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query fu…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2467

Published Dec 31, 2005

Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to vi…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2468

Published Dec 31, 2005

Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist f…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2558

Published Aug 16, 2005

Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create use…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2573

Published Aug 16, 2005

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1636

Published May 17, 2005

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local user…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0083

Published May 2, 2005

MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0709

Published May 2, 2005

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0710

Published May 2, 2005

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary lib…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0711

Published May 2, 2005

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to ov…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1274

Published Apr 26, 2005

Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP u…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0684

Published Apr 25, 2005

Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0081

Published Apr 14, 2005

MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0082

Published Apr 14, 2005

The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 112 CVEsPage 4 of 5