Количество 2 129
Количество 2 129
GHSA-pfvf-3927-r9fx
This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190.
GHSA-pc84-v5fr-8p3f
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.
GHSA-p388-7w8m-f48h
MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.
GHSA-p293-2w9f-jrwc
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock.
GHSA-mwgq-r782-4vx4
MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
GHSA-mvw8-35pm-hmgm
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
GHSA-m469-6q82-xqvx
An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
GHSA-m42w-339f-jp66
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
GHSA-jj99-6883-93g3
MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
GHSA-j6gf-pxm2-h6x5
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
GHSA-hx5h-h8m3-hvw4
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
GHSA-hpgh-p2hm-xrpr
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
GHSA-hc8h-974x-98hr
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.
GHSA-hc55-j7j2-f8w9
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.
GHSA-h8g7-9rx9-625q
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
GHSA-g3vp-fwv2-p6m7
An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
GHSA-fqhg-58rx-5ghm
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock.
GHSA-fpv9-9h63-pjx6
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.
GHSA-f8w6-xxmj-9fw4
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
GHSA-f3hf-23j8-mwgw
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-pfvf-3927-r9fx This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-pc84-v5fr-8p3f MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-p388-7w8m-f48h MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-p293-2w9f-jrwc MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-mwgq-r782-4vx4 MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-mvw8-35pm-hmgm MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-m469-6q82-xqvx An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-m42w-339f-jp66 An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-jj99-6883-93g3 MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-j6gf-pxm2-h6x5 MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-hx5h-h8m3-hvw4 MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-hpgh-p2hm-xrpr MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-hc8h-974x-98hr MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-hc55-j7j2-f8w9 MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-h8g7-9rx9-625q MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-g3vp-fwv2-p6m7 An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-fqhg-58rx-5ghm MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-fpv9-9h63-pjx6 MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-f8w6-xxmj-9fw4 MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-f3hf-23j8-mwgw MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу