Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 129

Количество 2 129

github логотип

GHSA-cxcg-577f-2582

почти 3 года назад

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cwg9-vp4r-v3q2

почти 3 года назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cw8p-532r-7gqx

около 3 лет назад

MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-99jw-w9c8-f6wv

около 3 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8rp2-7jc6-wrw4

почти 3 года назад

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8gjp-gp42-7qg3

около 3 лет назад

An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8c8g-735r-wqqj

больше 3 лет назад

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-85h8-46x6-w44w

почти 3 года назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-85fq-56wq-gmcf

почти 7 лет назад

Withdrawn Advisory: mariadb was malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7x2j-p87r-93gf

больше 3 лет назад

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-7php-c48c-5jgv

около 3 лет назад

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6hwc-564p-37h2

около 3 лет назад

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6589-j38p-mm8c

больше 1 года назад

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-53wc-v4mf-xrvp

около 3 лет назад

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5265-h4f9-w9cf

около 3 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v3m-fhx4-qp25

около 3 лет назад

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4mvf-f4q5-j3rq

около 3 лет назад

An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-48pm-mhwh-g6mr

около 3 лет назад

There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-44q2-c8m6-j2gg

почти 3 года назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xr8-q83f-2wqp

около 3 лет назад

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cxcg-577f-2582

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-cwg9-vp4r-v3q2

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-cw8p-532r-7gqx

MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-99jw-w9c8-f6wv

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-8rp2-7jc6-wrw4

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-8gjp-gp42-7qg3

An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-8c8g-735r-wqqj

This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-85h8-46x6-w44w

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-85fq-56wq-gmcf

Withdrawn Advisory: mariadb was malware

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
github логотип
GHSA-7x2j-p87r-93gf

MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7php-c48c-5jgv

MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-6hwc-564p-37h2

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-6589-j38p-mm8c

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-53wc-v4mf-xrvp

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-5265-h4f9-w9cf

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-4v3m-fhx4-qp25

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-4mvf-f4q5-j3rq

An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-48pm-mhwh-g6mr

There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-44q2-c8m6-j2gg

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3xr8-q83f-2wqp

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу