Vulnerabilities > Oracle > Mysql > 4.0.0

DATE CVE VULNERABILITY TITLE RISK
2004-05-04 CVE-2004-0381 mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.
local
low complexity
mysql oracle
2.1
2003-12-31 CVE-2003-1480 Cryptographic Issues vulnerability in multiple products
MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.
network
mysql oracle CWE-310
4.3
2003-09-22 CVE-2003-0780 Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
network
low complexity
mysql oracle conectiva
critical
9.0
2002-12-23 CVE-2002-1376 Buffer Overflow vulnerability in MySQL libmysqlclient Library Read_Rows
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
oracle symantec-veritas
7.5
2002-12-23 CVE-2002-1375 The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
network
low complexity
oracle symantec-veritas
7.5
2002-12-23 CVE-2002-1374 The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
network
low complexity
oracle symantec-veritas
7.5
2002-12-23 CVE-2002-1373 Unspecified vulnerability in Oracle Mysql
Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.
network
low complexity
oracle
5.0
2002-10-11 CVE-2002-0969 Classic Buffer Overflow vulnerability in Oracle Mysql
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
local
low complexity
oracle CWE-120
7.8