VYPR

Bitnami package

mariadb

pkg:bitnami/mariadb

Vulnerabilities (103)

  • CVE-2022-27448Apr 14, 2022
    affected >= 10.3.0, < 10.3.35fixed 10.3.35

    There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

  • CVE-2022-27447Apr 14, 2022
    affected >= 10.3.0, < 10.3.35fixed 10.3.35

    MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.

  • CVE-2022-27446Apr 14, 2022
    affected >= 10.4.0, < 10.4.25fixed 10.4.25

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.

  • CVE-2022-27445Apr 14, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

  • CVE-2022-27444Apr 14, 2022
    affected >= 10.4.0, < 10.4.25fixed 10.4.25

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.

  • CVE-2022-27387Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

  • CVE-2022-27386Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.

  • CVE-2022-27385Apr 12, 2022
    affected < 10.3.32fixed 10.3.32

    An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27384Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27383Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

  • CVE-2022-27382Apr 12, 2022
    affected >= 10.4.0, < 10.4.25fixed 10.4.25

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

  • CVE-2022-27381Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27380Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27379Apr 12, 2022
    affected >= 10.3.0, < 10.3.35fixed 10.3.35

    An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27378Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27377Apr 12, 2022
    affected >= 10.2.0, < 10.2.44fixed 10.2.44

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

  • CVE-2022-27376Apr 12, 2022
    affected >= 10.3.0, < 10.3.35fixed 10.3.35

    MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

  • CVE-2022-0778HigMar 15, 2022
    affected >= 10.2.0, < 10.2.42fixed 10.2.42

    The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curv

  • CVE-2022-24052Feb 18, 2022
    affected >= 10.2.0, < 10.2.42fixed 10.2.42

    MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists

  • CVE-2022-24051Feb 18, 2022
    affected >= 10.2.0, < 10.2.42fixed 10.2.42

    MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the pr

Page 3 of 6