Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 144

Количество 2 144

nvd логотип

CVE-2021-46658

больше 3 лет назад

save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-46658

больше 3 лет назад

save_window_function_values in MariaDB before 10.6.3 allows an applica ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2021-46657

больше 3 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46657

больше 4 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-46657

больше 3 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-46657

больше 3 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2020-7221

больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-7221

больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2020-7221

больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2020-7221

больше 5 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege es ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2020-28912

больше 4 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2020-28912

почти 5 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2020-28912

больше 4 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2020-28912

больше 4 лет назад

With MariaDB running on Windows, when local clients connect to the ser ...

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2017-16046

больше 7 лет назад

`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-08763

больше 1 года назад

Уязвимость библиотеки lib_mysqludf_sys.so системы управления базами данных MariaDB, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 5.7
EPSS: Средний
fstec логотип

BDU:2024-08759

больше 2 лет назад

Уязвимость пользовательских функций (UDF) системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2015-00597

больше 11 лет назад

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 6.8
EPSS: Низкий
fstec логотип

BDU:2015-00596

больше 11 лет назад

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4
EPSS: Низкий
fstec логотип

BDU:2015-00595

больше 11 лет назад

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-46658

save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-46658

save_window_function_values in MariaDB before 10.6.3 allows an applica ...

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash ...

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege es ...

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7.3
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the ser ...

CVSS3: 7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2017-16046

`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
fstec логотип
BDU:2024-08763

Уязвимость библиотеки lib_mysqludf_sys.so системы управления базами данных MariaDB, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 5.7
17%
Средний
больше 1 года назад
fstec логотип
BDU:2024-08759

Уязвимость пользовательских функций (UDF) системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
15%
Средний
больше 2 лет назад
fstec логотип
BDU:2015-00597

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
fstec логотип
BDU:2015-00596

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4
1%
Низкий
больше 11 лет назад
fstec логотип
BDU:2015-00595

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 6.8
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу