5.1

CVE-2012-2122

Exploit

sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.

Data is provided by the National Vulnerability Database (NVD)
OracleMysql Version5.1.51
OracleMysql Version5.1.52
OracleMysql Version5.1.52 Updatesp1
OracleMysql Version5.1.53
OracleMysql Version5.1.54
OracleMysql Version5.1.55
OracleMysql Version5.1.56
OracleMysql Version5.1.57
OracleMysql Version5.1.58
OracleMysql Version5.1.59
OracleMysql Version5.1.60
OracleMysql Version5.1.61
OracleMysql Version5.5.10
OracleMysql Version5.5.11
OracleMysql Version5.5.12
OracleMysql Version5.5.13
OracleMysql Version5.5.14
OracleMysql Version5.5.15
OracleMysql Version5.5.16
OracleMysql Version5.5.17
OracleMysql Version5.5.18
OracleMysql Version5.5.19
OracleMysql Version5.5.20
OracleMysql Version5.5.21
OracleMysql Version5.6.2
OracleMysql Version5.6.3
OracleMysql Version5.6.4
OracleMysql Version5.6.5
MariadbMariadb Version5.1.41
MariadbMariadb Version5.1.42
MariadbMariadb Version5.1.44
MariadbMariadb Version5.1.47
MariadbMariadb Version5.1.49
MariadbMariadb Version5.1.50
MariadbMariadb Version5.1.51
MariadbMariadb Version5.1.53
MariadbMariadb Version5.1.55
MariadbMariadb Version5.1.60
MariadbMariadb Version5.1.61
MariadbMariadb Version5.2.0
MariadbMariadb Version5.2.1
MariadbMariadb Version5.2.2
MariadbMariadb Version5.2.3
MariadbMariadb Version5.2.4
MariadbMariadb Version5.2.5
MariadbMariadb Version5.2.6
MariadbMariadb Version5.2.7
MariadbMariadb Version5.2.8
MariadbMariadb Version5.2.9
MariadbMariadb Version5.2.10
MariadbMariadb Version5.2.11
MariadbMariadb Version5.3.0
MariadbMariadb Version5.3.1
MariadbMariadb Version5.3.2
MariadbMariadb Version5.3.3
MariadbMariadb Version5.3.4
MariadbMariadb Version5.3.5
MariadbMariadb Version5.3.6
MariadbMariadb Version5.5.20
MariadbMariadb Version5.5.21
MariadbMariadb Version5.5.22
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.06% 0.999
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.