Skip to main content

Vendor/product archive

pingcap / tidb CVEs

Beta · best-effort

7 CVEs tagged to pingcap / tidb2 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-41433

Published Sep 3, 2024

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Servic…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41434

Published Sep 3, 2024

PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted inpu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35618

Published May 24, 2024

PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33809

Published May 24, 2024

PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3023

Published Nov 4, 2022

Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34969

Published Aug 3, 2022

PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31011

Published May 31, 2022

TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1