Логотип exploitDog
product: "mysql_server"
Консоль
Логотип exploitDog

exploitDog

product: "mysql_server"

Количество 1 319

Количество 1 319

debian логотип

CVE-2021-2389

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2021-2372

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2021-2372

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2021-2372

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2021-2372

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2021-22945

больше 4 лет назад

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2021-22945

больше 4 лет назад

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2021-22945

больше 4 лет назад

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2021-22945

больше 4 лет назад

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 coul ...

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1508-1

больше 6 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1492-1

больше 6 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2009-1

больше 6 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14064-1

больше 6 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1363-1

больше 6 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1357-2

больше 6 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1357-1

больше 6 лет назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-jg6g-8j59-vr29

почти 4 года назад

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hr98-frg6-wvvr

больше 3 лет назад

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-975f-fvhv-8mhx

больше 3 лет назад

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8xvc-p9x4-w7jm

больше 3 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2021-2389

Vulnerability in the MySQL Server product of Oracle MySQL (component: ...

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-2372

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-2372

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-2372

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-2372

Vulnerability in the MySQL Server product of Oracle MySQL (component: ...

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22945

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-22945

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22945

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22945

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 coul ...

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1508-1

Security update for curl

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1492-1

Security update for curl

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2009-1

Security update for curl

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14064-1

Security update for curl

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1363-1

Security update for curl

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1357-2

Security update for curl

3%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1357-1

Security update for curl

3%
Низкий
больше 6 лет назад
github логотип
GHSA-jg6g-8j59-vr29

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-hr98-frg6-wvvr

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-975f-fvhv-8mhx

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8xvc-p9x4-w7jm

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу