rpm package
almalinux/mysql
pkg:rpm/almalinux/mysql
Vulnerabilities (534)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-21198 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple | |
| CVE-2024-21197 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network acces | |
| CVE-2024-21196 | Med | 6.5 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multi | |
| CVE-2024-21194 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2024-21193 | Med | 4.9 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple p | |
| CVE-2024-7264 | Med | 6.5 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Jul 31, 2024 | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer t | |
| CVE-2024-37371 | Cri | 9.1 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Jun 28, 2024 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields. | |
| CVE-2024-5535 | Cri | 9.1 | < 8.0.41-2.el9_5 | 8.0.41-2.el9_5 | Jun 27, 2024 | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected appl | |
| CVE-2024-2097 | Hig | 7.5 | < 8.0.36-1.el9_3 | 8.0.36-1.el9_3 | Mar 27, 2024 | An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools. | |
| CVE-2024-20984 | Med | 4.4 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multipl | |
| CVE-2024-20982 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20978 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20976 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20974 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20972 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20970 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20968 | Med | 4.4 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromi | |
| CVE-2024-20966 | Med | 4.9 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t | |
| CVE-2024-20964 | Med | 5.3 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple | |
| CVE-2024-20962 | Med | 6.5 | < 8.0.36-1.module_el8.9.0+3735+82bd6c11 | 8.0.36-1.module_el8.9.0+3735+82bd6c11 | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to |
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network acces
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multi
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple p
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer t
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
- affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5
Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected appl
- affected < 8.0.36-1.el9_3fixed 8.0.36-1.el9_3
An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multipl
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromi
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple
- affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to
Page 9 of 27