Логотип exploitDog
bind:"CVE-2009-4019" OR bind:"CVE-2009-4030" OR bind:"CVE-2009-4028"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2009-4019" OR bind:"CVE-2009-4030" OR bind:"CVE-2009-4028"

Количество 18

Количество 18

oracle-oval логотип

ELSA-2010-0109

больше 15 лет назад

ELSA-2010-0109: mysql security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2009-4019

больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2009-4019

больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

CVSS2: 2.7
EPSS: Низкий
nvd логотип

CVE-2009-4019

больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2009-4019

больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not ( ...

CVSS2: 4
EPSS: Низкий
github логотип

GHSA-pvv2-gf98-5mv3

около 3 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

EPSS: Низкий
ubuntu логотип

CVE-2009-4030

больше 15 лет назад

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2009-4030

больше 15 лет назад

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS2: 2.4
EPSS: Низкий
nvd логотип

CVE-2009-4030

больше 15 лет назад

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS2: 4.4
EPSS: Низкий
debian логотип

CVE-2009-4030

больше 15 лет назад

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privile ...

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2009-4028

больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2009-4028

больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

CVSS2: 2.9
EPSS: Низкий
nvd логотип

CVE-2009-4028

больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-4028

больше 15 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x b ...

CVSS2: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2023:4991-1

больше 1 года назад

Recommended update for mariadb104

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2023:3956-1

больше 1 года назад

Recommended update for mariadb104

EPSS: Низкий
github логотип

GHSA-q8q6-rcmj-g45q

около 3 лет назад

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

EPSS: Низкий
github логотип

GHSA-7mf2-7qv8-9w8f

около 3 лет назад

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2010-0109

ELSA-2010-0109: mysql security update (MODERATE)

больше 15 лет назад
ubuntu логотип
CVE-2009-4019

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

CVSS2: 4
8%
Низкий
больше 15 лет назад
redhat логотип
CVE-2009-4019

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

CVSS2: 2.7
8%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4019

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

CVSS2: 4
8%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4019

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not ( ...

CVSS2: 4
8%
Низкий
больше 15 лет назад
github логотип
GHSA-pvv2-gf98-5mv3

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

8%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2009-4030

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS2: 4.4
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2009-4030

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS2: 2.4
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4030

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS2: 4.4
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4030

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privile ...

CVSS2: 4.4
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4028

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

CVSS2: 6.8
2%
Низкий
больше 15 лет назад
redhat логотип
CVE-2009-4028

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

CVSS2: 2.9
2%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4028

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

CVSS2: 6.8
2%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4028

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x b ...

CVSS2: 6.8
2%
Низкий
больше 15 лет назад
suse-cvrf логотип
SUSE-RU-2023:4991-1

Recommended update for mariadb104

больше 1 года назад
suse-cvrf логотип
SUSE-RU-2023:3956-1

Recommended update for mariadb104

больше 1 года назад
github логотип
GHSA-q8q6-rcmj-g45q

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

0%
Низкий
около 3 лет назад
github логотип
GHSA-7mf2-7qv8-9w8f

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.

2%
Низкий
около 3 лет назад

Уязвимостей на страницу