Vulnerabilities
Vulnerable Software
Mariadb:  >> Mariadb  >> 10.2.43  Security Vulnerabilities
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-04-12
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-04-12
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-04-12
An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-12
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-12
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-12
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-02-01
If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server.
CVSS Score
4.9
EPSS Score
0.009
Published
2017-08-05


Contact Us

Shodan ® - All rights reserved