Vulnerabilities > Oracle > Mysql > 5.1.26

DATE CVE VULNERABILITY TITLE RISK
2011-01-11 CVE-2010-3683 Denial Of Service vulnerability in Oracle MySQL 'LOAD DATA INFILE'
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a crafted request.
network
low complexity
mysql oracle
4.0
2011-01-11 CVE-2010-3682 Denial Of Service vulnerability in Oracle MySQL 'EXPLAIN'
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ...
network
low complexity
mysql oracle
4.0
2011-01-11 CVE-2010-3681 Denial Of Service vulnerability in Oracle MySQL 'HANDLER' interface
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
network
low complexity
mysql oracle
4.0
2011-01-11 CVE-2010-3680 Denial Of Service vulnerability in Oracle MySQL 'TEMPORARY InnoDB' Tables
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with nullable columns while using InnoDB, which triggers an assertion failure.
network
low complexity
mysql oracle
4.0
2011-01-11 CVE-2010-3679 Resource Management Errors vulnerability in multiple products
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an access of uninitialized memory, as demonstrated by valgrind.
network
low complexity
mysql oracle CWE-399
4.0
2011-01-11 CVE-2010-3678 Resource Management Errors vulnerability in multiple products
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
network
low complexity
mysql oracle CWE-399
4.0
2011-01-11 CVE-2010-3677 Resource Management Errors vulnerability in multiple products
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column.
network
low complexity
mysql oracle CWE-399
4.0
2011-01-11 CVE-2010-3676 Denial Of Service vulnerability in Oracle MySQL Prior to 5.1.49 'DDL' Statements
storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (1) innodb_file_format or (2) innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement.
network
low complexity
mysql oracle
4.0
2010-07-13 CVE-2010-2008 Command Injection vulnerability in multiple products
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a .
3.5
2009-11-30 CVE-2009-4028 Improper Input Validation vulnerability in multiple products
The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
network
mysql oracle CWE-20
6.8