CVE-2026-35549
- EPSS 0.06%
- Veröffentlicht 03.04.2026 05:16:23
- Zuletzt bearbeitet 03.04.2026 16:10:23
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet ca...
CVE-2026-32710
- EPSS 0.1%
- Veröffentlicht 20.03.2026 18:31:48
- Zuletzt bearbeitet 31.03.2026 21:13:18
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn...
CVE-2026-3494
- EPSS 0.02%
- Veröffentlicht 03.03.2026 18:12:12
- Zuletzt bearbeitet 16.03.2026 18:16:09
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with doub...
- EPSS 0.12%
- Veröffentlicht 23.12.2025 21:40:56
- Zuletzt bearbeitet 15.04.2026 00:35:42
MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to ...
CVE-2023-52969
- EPSS 0.46%
- Veröffentlicht 08.03.2025 23:15:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2.
CVE-2023-52970
- EPSS 0.46%
- Veröffentlicht 08.03.2025 23:15:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.
CVE-2023-52971
- EPSS 0.08%
- Veröffentlicht 08.03.2025 23:15:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
CVE-2023-52968
- EPSS 0.02%
- Veröffentlicht 08.03.2025 23:15:13
- Zuletzt bearbeitet 15.04.2026 00:35:42
MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leadi...
CVE-2023-26785
- EPSS 63.02%
- Veröffentlicht 17.10.2024 22:15:02
- Zuletzt bearbeitet 10.07.2025 19:06:29
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is cro...
CVE-2023-39593
- EPSS 0.79%
- Veröffentlicht 17.10.2024 22:15:02
- Zuletzt bearbeitet 10.07.2025 19:09:33
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.