VYPR

Vendor CVEs

MariaDB

All CVEs

423 total · sorted by risk
  • CVE-2016-6662CriSep 20, 2016
    risk 0.72cvss 9.8epss 0.68

    Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary…

  • CVE-2026-44172CriJun 12, 2026
    risk 0.64cvss 9.8epss 0.01

    MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was…

  • CVE-2026-44170CriJun 12, 2026
    risk 0.64cvss 9.8epss 0.01

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated…

  • CVE-2023-26785CriOct 17, 2024
    risk 0.64cvss 9.8epss 0.02

    MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

  • CVE-2016-9843CriMay 23, 2017
    risk 0.64cvss 9.8epss 0.06

    The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

  • CVE-2020-15180CriMay 27, 2021
    risk 0.59cvss 9.0epss 0.06

    A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality,…

  • CVE-2014-0224HigJun 5, 2014
    risk 0.59cvss 7.4epss 0.95

    OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and…

  • CVE-2026-49261CriJun 11, 2026
    risk 0.58cvss 10.0epss 0.02

    MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner…

  • CVE-2021-27928HigMar 19, 2021
    risk 0.53cvss 7.2epss 0.38

    A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection,…

  • CVE-2016-3477HigJul 21, 2016
    risk 0.53cvss 8.1epss 0.00

    Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to…

  • CVE-2026-48165HigJun 12, 2026
    risk 0.52cvss 8.0epss 0.02

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or…

  • CVE-2026-48163HigJun 12, 2026
    risk 0.52cvss 8.0epss 0.01

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into…

  • CVE-2026-44168HigJun 12, 2026
    risk 0.52cvss 8.0epss 0.01

    MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into…

  • CVE-2022-24052HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.01

    MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2022-24051HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.01

    MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2022-24050HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.01

    MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2022-24048HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.01

    MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2015-2325HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.02

    The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward…

  • CVE-2017-15945HigOct 27, 2017
    risk 0.51cvss 7.8epss 0.00

    The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging…

  • CVE-2017-3309HigApr 24, 2017
    risk 0.50cvss 7.7epss 0.03

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network…

  • CVE-2017-3308HigApr 24, 2017
    risk 0.50cvss 7.7epss 0.03

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access…

  • CVE-2025-56404HigSep 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.

  • CVE-2023-5157HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

  • CVE-2022-32091HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

  • CVE-2022-32089HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

  • CVE-2022-32088HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

  • CVE-2022-32087HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.

  • CVE-2022-32086HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

  • CVE-2022-32085HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

  • CVE-2022-32084HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.

  • CVE-2022-32083HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

  • CVE-2022-32082HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.

  • CVE-2022-32081HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.

  • CVE-2022-27457HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.

  • CVE-2022-27456HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.

  • CVE-2022-27455HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.

  • CVE-2022-27452HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.

  • CVE-2022-27451HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.

  • CVE-2022-27449HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.

  • CVE-2022-27448HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

  • CVE-2022-27447HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.

  • CVE-2022-27446HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.

  • CVE-2022-27445HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.

  • CVE-2022-27444HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.

  • CVE-2022-27387HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

  • CVE-2022-27386HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.

  • CVE-2022-27385HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27384HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27383HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

  • CVE-2022-27382HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

Page 1 of 9