CVE-2007-2693
- EPSS 0.48%
- Veröffentlicht 16.05.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
- EPSS 3.26%
- Veröffentlicht 10.05.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL poin...
CVE-2007-1420
- EPSS 0.06%
- Veröffentlicht 12.03.2007 23:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialize...
CVE-2006-4226
- EPSS 0.81%
- Veröffentlicht 18.08.2006 20:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have pe...
CVE-2006-4227
- EPSS 11.49%
- Veröffentlicht 18.08.2006 20:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has bee...
CVE-2006-4031
- EPSS 0.24%
- Veröffentlicht 09.08.2006 22:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
- EPSS 47.88%
- Veröffentlicht 21.07.2006 14:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_forma...
CVE-2006-3486
- EPSS 0.09%
- Veröffentlicht 10.07.2006 21:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) ...
- EPSS 10.14%
- Veröffentlicht 19.06.2006 18:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
CVE-2006-2753
- EPSS 6.99%
- Veröffentlicht 01.06.2006 17:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properl...