Vulnerabilities
Vulnerable Software
Mariadb:  >> Mariadb  >> 10.4.13  Security Vulnerabilities
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
CVSS Score
7.5
EPSS Score
0.004
Published
2022-02-01
MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-02-01
get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-01-29
save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-01-29
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
CVSS Score
5.5
EPSS Score
0.0
Published
2022-01-29


Contact Us

Shodan ® - All rights reserved