Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"
MariaDB

MariaDBответвление от системы управления базами данных MySQL, разрабатываемое сообществом под лицензией GNU GPL.

Релизный цикл, информация об уязвимостях

Продукт: MariaDB
Вендор: mariadb

График релизов

10.610.710.810.910.1010.1111.011.111.211.311.411.511.611.711.812.012.12021202220232024202520262027202820292030

Недавние уязвимости MariaDB

Количество 2 149

debian логотип

CVE-2020-15180

больше 4 лет назад

A flaw was found in the mysql-wsrep component of mariadb. Lack of inpu ...

CVSS3: 9
EPSS: Низкий
ubuntu логотип

CVE-2020-15180

больше 4 лет назад

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

CVSS3: 9
EPSS: Низкий
redhat логотип

CVE-2021-46668

больше 4 лет назад

MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46661

больше 4 лет назад

MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46664

больше 4 лет назад

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46662

почти 5 лет назад

MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46669

почти 5 лет назад

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-46659

почти 5 лет назад

MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46665

почти 5 лет назад

MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46666

почти 5 лет назад

MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2020-15180

A flaw was found in the mysql-wsrep component of mariadb. Lack of inpu ...

CVSS3: 9
3%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-15180

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

CVSS3: 9
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-46668

MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-46661

MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-46664

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-46662

MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-46669

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-46659

MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-46665

MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-46666

MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.

CVSS3: 5.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу


Поделиться