Vulnerabilities > Mysql > Low

DATE CVE VULNERABILITY TITLE RISK
2007-03-12 CVE-2007-1420 Remote Denial Of Service vulnerability in MySQL Single Row SubSelect
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
local
low complexity
mysql oracle
2.1
2006-12-31 CVE-2006-7232 SQL Injection vulnerability in multiple products
sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
3.5
2006-08-28 CVE-2006-4380 Denial Of Service vulnerability in Mysql 4.1.13
MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.
local
low complexity
mysql
2.1
2006-08-18 CVE-2006-4226 MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions.
network
high complexity
mysql oracle
3.6
2006-08-09 CVE-2006-4031 MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
local
low complexity
mysql oracle
2.1
2005-05-02 CVE-2005-0711 Remote vulnerability in MySQL AB MySQL
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
local
low complexity
mysql oracle
2.1
2004-05-04 CVE-2004-0381 mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.
local
low complexity
mysql oracle
2.1