VYPR

rpm package

almalinux/mysql

pkg:rpm/almalinux/mysql

Vulnerabilities (534)

  • CVE-2024-21198MedOct 15, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple

  • CVE-2024-21197MedOct 15, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network acces

  • CVE-2024-21196MedOct 15, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multi

  • CVE-2024-21194MedOct 15, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto

  • CVE-2024-21193MedOct 15, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple p

  • CVE-2024-7264MedJul 31, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer t

  • CVE-2024-37371CriJun 28, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

  • CVE-2024-5535CriJun 27, 2024
    affected < 8.0.41-2.el9_5fixed 8.0.41-2.el9_5

    Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent to the peer. Impact summary: A buffer overread can have a range of potential consequences such as unexpected appl

  • CVE-2024-2097HigMar 27, 2024
    affected < 8.0.36-1.el9_3fixed 8.0.36-1.el9_3

    An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.

  • CVE-2024-20984MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multipl

  • CVE-2024-20982MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20978MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20976MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20974MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20972MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20970MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20968MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromi

  • CVE-2024-20966MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols t

  • CVE-2024-20964MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple

  • CVE-2024-20962MedFeb 17, 2024
    affected < 8.0.36-1.module_el8.9.0+3735+82bd6c11fixed 8.0.36-1.module_el8.9.0+3735+82bd6c11

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to

Page 9 of 27