Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"
MariaDB

MariaDBответвление от системы управления базами данных MySQL, разрабатываемое сообществом под лицензией GNU GPL.

Релизный цикл, информация об уязвимостях

Продукт: MariaDB
Вендор: mariadb

График релизов

10.610.710.810.910.1010.1111.011.111.211.311.411.511.611.711.812.012.12021202220232024202520262027202820292030

Недавние уязвимости MariaDB

Количество 2 149

debian логотип

CVE-2016-2047

около 10 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-2047

около 10 лет назад

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2015-7744

около 10 лет назад

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2015-7744

около 10 лет назад

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2015-7744

около 10 лет назад

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2016-0616

около 10 лет назад

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2016-0616

около 10 лет назад

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and Maria ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2016-0610

около 10 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2016-0610

около 10 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and Maria ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2016-0609

около 10 лет назад

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.

CVSS2: 1.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB ...

CVSS3: 5.9
2%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-2047

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

CVSS3: 5.9
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-7744

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

CVSS3: 5.9
3%
Низкий
около 10 лет назад
debian логотип
CVE-2015-7744

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults ...

CVSS3: 5.9
3%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-7744

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

CVSS3: 5.9
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-0616

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2016-0616

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and Maria ...

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-0610

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

CVSS2: 3.5
1%
Низкий
около 10 лет назад
debian логотип
CVE-2016-0610

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and Maria ...

CVSS2: 3.5
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-0609

Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.

CVSS2: 1.7
1%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться