Vulnerabilities > Mysql > Mysql

DATE CVE VULNERABILITY TITLE RISK
2006-08-09 CVE-2006-4031 MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
local
low complexity
mysql oracle
2.1
2006-07-21 CVE-2006-3469 USE of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
network
low complexity
mysql oracle CWE-134
4.0
2006-06-19 CVE-2006-3081 Remote Denial Of Service vulnerability in MySQL Server Str_To_Date
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
network
low complexity
mysql oracle
4.0
2006-06-01 CVE-2006-2753 SQL Injection vulnerability in MySQL Mysql_real_escape Function
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the input.
network
low complexity
mysql oracle
7.5
2006-05-05 CVE-2006-1518 Remote Information Disclosure and Buffer Overflow vulnerability in MySQL
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.
network
low complexity
mysql oracle
6.5
2006-05-05 CVE-2006-1517 Remote Information Disclosure and Buffer Overflow vulnerability in MySQL
sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.
network
low complexity
mysql oracle
5.0
2006-05-05 CVE-2006-1516 Remote Information Disclosure and Buffer Overflow vulnerability in MySQL
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.
network
low complexity
mysql oracle
5.0
2005-08-16 CVE-2005-2558 Buffer Overflow vulnerability in MySQL User-Defined Function
Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.
local
low complexity
mysql oracle
4.6
2005-05-17 CVE-2005-1636 mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.
local
low complexity
mysql oracle
4.6
2005-05-02 CVE-2005-0711 Remote vulnerability in MySQL AB MySQL
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
local
low complexity
mysql oracle
2.1