Vulnerabilities
Vulnerable Software
Mariadb:  >> Mariadb  >> 10.7.2  Security Vulnerabilities
MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-04-12
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-04-12
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-12
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-12
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-03-25
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-02-01
MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01


Contact Us

Shodan ® - All rights reserved