VYPR

Bitnami package

mariadb

pkg:bitnami/mariadb

Vulnerabilities (116)

  • CVE-2021-2011MedJan 20, 2021
    affected >= 5.5.0, < 5.5.61fixed 5.5.61

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromis

  • CVE-2021-2007LowJan 20, 2021
    affected >= 5.5.0, < 5.5.65fixed 5.5.65

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple prot

  • CVE-2020-28912HigDec 24, 2020
    affected < 10.1.48fixed 10.1.48

    With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the da

  • CVE-2020-14812MedOct 21, 2020
    affected >= 10.1.0, < 10.1.48fixed 10.1.48

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multi

  • CVE-2020-14789MedOct 21, 2020
    affected >= 10.2.0, < 10.2.35fixed 10.2.35

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compr

  • CVE-2020-14776MedOct 21, 2020
    affected >= 10.2.0, < 10.2.35fixed 10.2.35

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise

  • CVE-2020-14765MedOct 21, 2020
    affected >= 10.1.0, < 10.1.48fixed 10.1.48

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple p

  • CVE-2020-14550MedJul 15, 2020
    affected >= 5.5.0, < 5.5.61fixed 5.5.61

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple proto

  • CVE-2020-2922LowApr 15, 2020
    affected >= 5.5.0, < 5.5.65fixed 5.5.65

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple prot

  • CVE-2020-2814MedApr 15, 2020
    affected >= 10.1.0, < 10.1.45fixed 10.1.45

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.47 and prior, 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto

  • CVE-2020-2812MedApr 15, 2020
    affected >= 5.5.0, < 5.5.68fixed 5.5.68

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access

  • CVE-2020-2780MedApr 15, 2020
    affected >= 5.5.0, < 5.5.66fixed 5.5.66

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple p

  • CVE-2020-2760MedApr 15, 2020
    affected >= 10.2.0, < 10.2.32fixed 10.2.32

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise

  • CVE-2020-2752MedApr 15, 2020
    affected >= 5.5.0, < 5.5.68fixed 5.5.68

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple proto

  • CVE-2020-7221HigFeb 4, 2020
    affected >= 10.4.7, < 10.4.12fixed 10.4.12

    mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect t

  • CVE-2020-2574MedJan 15, 2020
    affected >= 5.5.0, < 5.5.67fixed 5.5.67

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.46 and prior, 5.7.28 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple prot

Page 6 of 6