CVE-2002-1923
- EPSS 0.71%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.
- EPSS 3.12%
- Veröffentlicht 23.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.
CVE-2002-1374
- EPSS 25.36%
- Veröffentlicht 23.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the fi...
CVE-2002-1375
- EPSS 15.03%
- Veröffentlicht 23.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
CVE-2002-1376
- EPSS 3.02%
- Veröffentlicht 23.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and po...
CVE-2002-0969
- EPSS 0.1%
- Veröffentlicht 11.10.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allo...
CVE-2001-1255
- EPSS 0.14%
- Veröffentlicht 02.10.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
CVE-2001-0407
- EPSS 0.71%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
CVE-2001-1453
- EPSS 11.66%
- Veröffentlicht 09.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
CVE-2001-1454
- EPSS 11.85%
- Veröffentlicht 09.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.