Vulnerabilities > Oracle > Mysql > 4.1.3

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0710 Remote vulnerability in MySQL AB MySQL
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
local
low complexity
mysql oracle
4.6
2005-05-02 CVE-2005-0709 Code Injection vulnerability in multiple products
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
local
low complexity
mysql oracle CWE-94
4.6
2005-04-14 CVE-2005-0004 Link Following vulnerability in multiple products
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
local
low complexity
oracle debian mariadb CWE-59
4.6
2004-12-31 CVE-2004-2149 Remote Buffer Overflow vulnerability in MySQL Bounded Parameter Statement Execution
Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.
network
low complexity
oracle
5.0