Skip to main content

Vendor/product archive

oracle / mysql CVEs

Beta · best-effort

1,326 CVEs tagged to oracle / mysql12 Critical, 70 High, 1,062 Medium, 182 Low, 0 Unrated.

CVE-2010-1850

Published Jun 8, 2010

Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1849

Published Jun 8, 2010

The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumpt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1848

Published Jun 8, 2010

Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1626

Published May 21, 2010

MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a differe…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4030

Published Nov 30, 2009

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4028

Published Nov 30, 2009

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 ce…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4019

Published Nov 30, 2009

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) pre…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7247

Published Nov 30, 2009

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2446

Published Jul 13, 2009

Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0819

Published Mar 5, 2009

sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a sc…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4456

Published Oct 6, 2008

Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4097

Published Sep 18, 2008

MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments tha…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3963

Published Sep 11, 2008

MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6303

Published Dec 10, 2007

MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated use…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6304

Published Dec 10, 2007

The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5970

Published Dec 10, 2007

MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2692

Published May 16, 2007

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routin…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2693

Published May 16, 2007

MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-1420

Published Mar 12, 2007

MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4226

Published Aug 18, 2006

MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the da…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort
Showing 1,251-1,275 of 1,326 CVEsPage 51 of 54