Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 149

Количество 2 149

nvd логотип

CVE-2021-46658

около 4 лет назад

save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-46658

около 4 лет назад

save_window_function_values in MariaDB before 10.6.3 allows an applica ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2021-46657

около 4 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2021-46657

больше 4 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-46657

около 4 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-46657

около 4 лет назад

get_sort_by_table in MariaDB before 10.6.2 allows an application crash ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2020-7221

около 6 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-7221

около 6 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2020-7221

около 6 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2020-7221

около 6 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege es ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2020-28912

около 5 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2020-28912

около 5 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2020-28912

около 5 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2020-28912

около 5 лет назад

With MariaDB running on Windows, when local clients connect to the ser ...

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2017-16046

больше 7 лет назад

`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-00803

6 месяцев назад

Уязвимость компонента mariadb-dump системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
EPSS: Низкий
fstec логотип

BDU:2024-08763

почти 2 года назад

Уязвимость библиотеки lib_mysqludf_sys.so системы управления базами данных MariaDB, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 5.7
EPSS: Средний
fstec логотип

BDU:2024-08759

почти 3 года назад

Уязвимость пользовательских функций (UDF) системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2015-00597

около 12 лет назад

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 6.8
EPSS: Низкий
fstec логотип

BDU:2015-00596

около 12 лет назад

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-46658

save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-46658

save_window_function_values in MariaDB before 10.6.3 allows an applica ...

CVSS3: 5.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-46657

get_sort_by_table in MariaDB before 10.6.2 allows an application crash ...

CVSS3: 5.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
debian логотип
CVE-2020-7221

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege es ...

CVSS3: 7.8
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7.3
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

CVSS3: 7
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-28912

With MariaDB running on Windows, when local clients connect to the ser ...

CVSS3: 7
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2017-16046

`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
fstec логотип
BDU:2026-00803

Уязвимость компонента mariadb-dump системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2024-08763

Уязвимость библиотеки lib_mysqludf_sys.so системы управления базами данных MariaDB, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 5.7
25%
Средний
почти 2 года назад
fstec логотип
BDU:2024-08759

Уязвимость пользовательских функций (UDF) системы управления базами данных MariaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
57%
Средний
почти 3 года назад
fstec логотип
BDU:2015-00597

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 6.8
1%
Низкий
около 12 лет назад
fstec логотип
BDU:2015-00596

Уязвимость программного обеспечения MariaDB Server, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4
1%
Низкий
около 12 лет назад

Уязвимостей на страницу