rpm package
almalinux/mysql-common
pkg:rpm/almalinux/mysql-common
Vulnerabilities (534)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-21494 | Med | 4.1 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to | |
| CVE-2025-21491 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2025-21490 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2024-13176 | Med | 4.1 | < 8.4.6-1.module_el9.6.0+180+a4e757e5 | 8.4.6-1.module_el9.6.0+180+a4e757e5 | Jan 20, 2025 | Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measurin | |
| CVE-2024-11053 | Low | 3.4 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Dec 11, 2024 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect | |
| CVE-2024-21247 | Low | 3.8 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mul | |
| CVE-2024-21241 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mul | |
| CVE-2024-21239 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2024-21238 | Med | 5.3 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.1 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access v | |
| CVE-2024-21237 | Low | 2.2 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network | |
| CVE-2024-21236 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2024-21231 | Low | 3.1 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via mult | |
| CVE-2024-21230 | Med | 6.5 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mult | |
| CVE-2024-21219 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple | |
| CVE-2024-21218 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2024-21213 | Med | 4.2 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where | |
| CVE-2024-21212 | Med | 4.4 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Health Monitor). Supported versions that are affected are 8.0.39 and prior and 8.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to c | |
| CVE-2024-21203 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple | |
| CVE-2024-21201 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mul | |
| CVE-2024-21199 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto |
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected < 8.4.6-1.module_el9.6.0+180+a4e757e5fixed 8.4.6-1.module_el9.6.0+180+a4e757e5
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measurin
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mul
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mul
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.1 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access v
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via mult
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mult
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Health Monitor). Supported versions that are affected are 8.0.39 and prior and 8.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to c
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via mul
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
Page 8 of 27