Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"
MariaDB

MariaDBответвление от системы управления базами данных MySQL, разрабатываемое сообществом под лицензией GNU GPL.

Релизный цикл, информация об уязвимостях

Продукт: MariaDB
Вендор: mariadb

График релизов

10.610.710.810.910.1010.1111.011.111.211.311.411.511.611.711.812.02021202220232024202520262027202820292030

Недавние уязвимости MariaDB

Количество 2 144

ubuntu логотип

CVE-2014-2494

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-4207

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-3470

больше 11 лет назад

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.

CVSS2: 4.3
EPSS: Критический
debian логотип

CVE-2014-3470

больше 11 лет назад

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL bef ...

CVSS2: 4.3
EPSS: Критический
nvd логотип

CVE-2014-0224

больше 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS3: 7.4
EPSS: Высокий
debian логотип

CVE-2014-0224

больше 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h d ...

CVSS3: 7.4
EPSS: Высокий
nvd логотип

CVE-2014-0221

больше 11 лет назад

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

CVSS2: 4.3
EPSS: Высокий
debian логотип

CVE-2014-0221

больше 11 лет назад

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 4.3
EPSS: Высокий
nvd логотип

CVE-2014-0195

больше 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
EPSS: Критический
debian логотип

CVE-2014-0195

больше 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 6.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2014-2494

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.

CVSS2: 4
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-4207

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.

CVSS2: 4
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-3470

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.

CVSS2: 4.3
91%
Критический
больше 11 лет назад
debian логотип
CVE-2014-3470

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL bef ...

CVSS2: 4.3
91%
Критический
больше 11 лет назад
nvd логотип
CVE-2014-0224

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS3: 7.4
90%
Высокий
больше 11 лет назад
debian логотип
CVE-2014-0224

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h d ...

CVSS3: 7.4
90%
Высокий
больше 11 лет назад
nvd логотип
CVE-2014-0221

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

CVSS2: 4.3
83%
Высокий
больше 11 лет назад
debian логотип
CVE-2014-0221

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 4.3
83%
Высокий
больше 11 лет назад
nvd логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
91%
Критический
больше 11 лет назад
debian логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 6.8
91%
Критический
больше 11 лет назад

Уязвимостей на страницу


Поделиться