Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 149

Количество 2 149

github логотип

GHSA-fpv9-9h63-pjx6

почти 4 года назад

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f8w6-xxmj-9fw4

почти 4 года назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-f3hf-23j8-mwgw

около 4 лет назад

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cxcg-577f-2582

больше 3 лет назад

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cwg9-vp4r-v3q2

больше 3 лет назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cw8p-532r-7gqx

почти 4 года назад

MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-99jw-w9c8-f6wv

почти 4 года назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8rp2-7jc6-wrw4

больше 3 лет назад

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8gjp-gp42-7qg3

почти 4 года назад

An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8c8g-735r-wqqj

почти 4 года назад

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-85h8-46x6-w44w

больше 3 лет назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-85fq-56wq-gmcf

больше 7 лет назад

Withdrawn Advisory: mariadb was malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7x2j-p87r-93gf

около 4 лет назад

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-7php-c48c-5jgv

почти 4 года назад

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6hwc-564p-37h2

почти 4 года назад

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6589-j38p-mm8c

больше 2 лет назад

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-53wc-v4mf-xrvp

почти 4 года назад

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5265-h4f9-w9cf

почти 4 года назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v3m-fhx4-qp25

почти 4 года назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4mvf-f4q5-j3rq

почти 4 года назад

An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fpv9-9h63-pjx6

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-f8w6-xxmj-9fw4

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-f3hf-23j8-mwgw

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-cxcg-577f-2582

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cwg9-vp4r-v3q2

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cw8p-532r-7gqx

MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-99jw-w9c8-f6wv

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-8rp2-7jc6-wrw4

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8gjp-gp42-7qg3

An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-8c8g-735r-wqqj

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-85h8-46x6-w44w

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-85fq-56wq-gmcf

Withdrawn Advisory: mariadb was malware

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
github логотип
GHSA-7x2j-p87r-93gf

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-7php-c48c-5jgv

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-6hwc-564p-37h2

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-6589-j38p-mm8c

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-53wc-v4mf-xrvp

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-5265-h4f9-w9cf

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4v3m-fhx4-qp25

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4mvf-f4q5-j3rq

An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу