Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 149

Количество 2 149

ubuntu логотип

CVE-2014-0198

почти 12 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2014-0198

почти 12 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2014-0198

почти 12 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2014-0198

почти 12 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2014-0195

больше 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
EPSS: Критический
redhat логотип

CVE-2014-0195

больше 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 5.8
EPSS: Критический
nvd логотип

CVE-2014-0195

больше 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
EPSS: Критический
debian логотип

CVE-2014-0195

больше 11 лет назад

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 6.8
EPSS: Критический
ubuntu логотип

CVE-2014-0001

около 12 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
EPSS: Средний
redhat логотип

CVE-2014-0001

около 12 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2014-0001

около 12 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-0001

около 12 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2013-5908

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-5908

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-5908

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2013-5908

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2013-5891

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-5891

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-5891

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-5891

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
31%
Средний
почти 12 лет назад
redhat логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
31%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS2: 4.3
31%
Средний
почти 12 лет назад
debian логотип
CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, ...

CVSS2: 4.3
31%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
93%
Критический
больше 11 лет назад
redhat логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 5.8
93%
Критический
больше 11 лет назад
nvd логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

CVSS2: 6.8
93%
Критический
больше 11 лет назад
debian логотип
CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before ...

CVSS2: 6.8
93%
Критический
больше 11 лет назад
ubuntu логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
21%
Средний
около 12 лет назад
redhat логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 4
21%
Средний
около 12 лет назад
nvd логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
21%
Средний
около 12 лет назад
debian логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before ...

CVSS2: 7.5
21%
Средний
около 12 лет назад
ubuntu логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
5%
Низкий
около 12 лет назад
redhat логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
5%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote attackers to affect availability via unknown vectors related to Error Handling.

CVSS2: 2.6
5%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5908

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 2.6
5%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
0%
Низкий
около 12 лет назад
redhat логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

CVSS2: 4
0%
Низкий
около 12 лет назад
debian логотип
CVE-2013-5891

Unspecified vulnerability in the MySQL Server component in Oracle MySQ ...

CVSS2: 4
0%
Низкий
около 12 лет назад

Уязвимостей на страницу