VYPR

MariaDB

by MariaDB

Source repositories

CVEs (416)

  • CVE-2026-44171MedJun 12, 2026
    risk 0.41cvss 6.3epss 0.00

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper…

  • CVE-2017-3291MedJan 27, 2017
    risk 0.41cvss 6.3epss 0.00

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to…

  • CVE-2016-0640MedApr 21, 2016
    risk 0.40cvss 6.1epss 0.01

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.

  • CVE-2021-2389MedJul 21, 2021
    risk 0.39cvss 5.9epss 0.08

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…

  • CVE-2021-2011MedJan 20, 2021
    risk 0.39cvss 5.9epss 0.03

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…

  • CVE-2015-7744MedJan 22, 2016
    risk 0.39cvss 5.9epss 0.05

    wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA…

  • CVE-2024-27766MedOct 17, 2024
    risk 0.37cvss 5.7epss 0.01

    An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

  • CVE-2017-3265MedJan 27, 2017
    risk 0.37cvss 5.6epss 0.01

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to…

  • CVE-2023-39593MedOct 17, 2024
    risk 0.36cvss 5.6epss 0.01

    Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

  • CVE-2022-38791MedAug 27, 2022
    risk 0.36cvss 5.5epss 0.00

    In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.

  • CVE-2021-46668MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

  • CVE-2021-46667MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

  • CVE-2021-46666MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.

  • CVE-2021-46665MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.

  • CVE-2021-46664MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.

  • CVE-2021-46663MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.

  • CVE-2021-46662MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.

  • CVE-2021-46661MedFeb 1, 2022
    risk 0.36cvss 5.5epss 0.00

    MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).

  • CVE-2021-46659MedJan 29, 2022
    risk 0.36cvss 5.5epss 0.01

    MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.

  • CVE-2021-46658MedJan 29, 2022
    risk 0.36cvss 5.5epss 0.00

    save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.

Page 6 of 21