Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 144

Количество 2 144

redhat логотип

CVE-2014-0198

больше 11 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2014-0198

больше 11 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2014-0198

больше 11 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2014-0195

около 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
EPSS: Критический
redhat логотип

CVE-2014-0195

около 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 5.8
EPSS: Критический
nvd логотип

CVE-2014-0195

около 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
EPSS: Критический
debian логотип

CVE-2014-0195

около 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 6.8
EPSS: Критический
ubuntu логотип

CVE-2014-0001

больше 11 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2014-0001

больше 11 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2014-0001

больше 11 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-0001

больше 11 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2013-5908

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-5908

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-5908

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2013-5908

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2013-5891

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-5891

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-5891

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-5891

больше 11 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-5807

почти 12 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
35%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
35%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, ...

CVSS2: 4.3
35%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
92%
Критический
около 11 лет назад
redhat логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 5.8
92%
Критический
около 11 лет назад
nvd логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
92%
Критический
около 11 лет назад
debian логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 6.8
92%
Критический
около 11 лет назад
ubuntu логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
20%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 4
20%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
20%
Средний
больше 11 лет назад
debian логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before ...

CVSS2: 7.5
20%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
6%
Низкий
больше 11 лет назад
redhat логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
6%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
6%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 2.6
6%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 4
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2013-5807

Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.

CVSS2: 4.9
0%
Низкий
почти 12 лет назад

Уязвимостей на страницу