Логотип exploitDog
product: "mariadb"
Консоль
Логотип exploitDog

exploitDog

product: "mariadb"

Количество 2 144

Количество 2 144

nvd логотип

CVE-2023-39593

10 месяцев назад

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.6
EPSS: Низкий
debian логотип

CVE-2023-39593

10 месяцев назад

Insecure permissions in the sys_exec function of MariaDB v10.5 allows ...

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2023-26785

10 месяцев назад

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2023-26785

10 месяцев назад

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.5
EPSS: Средний
nvd логотип

CVE-2023-26785

10 месяцев назад

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2023-26785

10 месяцев назад

MariaDB v10.5 was discovered to contain a remote code execution (RCE) ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2022-47015

больше 2 лет назад

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-47015

почти 3 года назад

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-47015

больше 2 лет назад

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-47015

больше 2 лет назад

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of S ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-38791

почти 3 года назад

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-38791

около 3 лет назад

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-38791

почти 3 года назад

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-38791

почти 3 года назад

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compr ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-32091

около 3 лет назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-32091

почти 4 года назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-32091

около 3 лет назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-32091

около 3 лет назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __in ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-32089

около 3 лет назад

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-32089

почти 4 года назад

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-39593

Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.6
1%
Низкий
10 месяцев назад
debian логотип
CVE-2023-39593

Insecure permissions in the sys_exec function of MariaDB v10.5 allows ...

CVSS3: 5.6
1%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2023-26785

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 9.8
14%
Средний
10 месяцев назад
redhat логотип
CVE-2023-26785

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 5.5
14%
Средний
10 месяцев назад
nvd логотип
CVE-2023-26785

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVSS3: 9.8
14%
Средний
10 месяцев назад
debian логотип
CVE-2023-26785

MariaDB v10.5 was discovered to contain a remote code execution (RCE) ...

CVSS3: 9.8
14%
Средний
10 месяцев назад
ubuntu логотип
CVE-2022-47015

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-47015

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-47015

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-47015

MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of S ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-38791

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-38791

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-38791

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-38791

In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compr ...

CVSS3: 5.5
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-32091

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-32091

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-32091

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-32091

MariaDB v10.7 was discovered to contain an use-after-poison in in __in ...

CVSS3: 7.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-32089

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-32089

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVSS3: 6.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу