Vulnerabilities > Debian > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-14 | CVE-2022-27456 | Use After Free vulnerability in multiple products MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc. | 7.5 |
2022-04-12 | CVE-2022-27376 | Use After Free vulnerability in multiple products MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27377 | Use After Free vulnerability in multiple products MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27378 | SQL Injection vulnerability in multiple products An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27379 | SQL Injection vulnerability in multiple products An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27380 | SQL Injection vulnerability in multiple products An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27381 | SQL Injection vulnerability in multiple products An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27383 | Use After Free vulnerability in multiple products MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27384 | SQL Injection vulnerability in multiple products An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | 7.5 |
2022-04-12 | CVE-2022-27386 | SQL Injection vulnerability in multiple products MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc. | 7.5 |