CVE-2006-4227
- EPSS 13.14%
- Veröffentlicht 18.08.2006 20:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has bee...
CVE-2006-4031
- EPSS 0.24%
- Veröffentlicht 09.08.2006 22:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
- EPSS 38.92%
- Veröffentlicht 21.07.2006 14:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_forma...
CVE-2006-3486
- EPSS 0.09%
- Veröffentlicht 10.07.2006 21:05:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) ...
- EPSS 13.05%
- Veröffentlicht 19.06.2006 18:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.
CVE-2006-2753
- EPSS 6.08%
- Veröffentlicht 01.06.2006 17:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properl...
- EPSS 82.33%
- Veröffentlicht 05.05.2006 12:46:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.
- EPSS 9.19%
- Veröffentlicht 05.05.2006 12:46:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error m...
CVE-2006-1518
- EPSS 42.79%
- Veröffentlicht 05.05.2006 12:46:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.
CVE-2006-0903
- EPSS 0.22%
- Veröffentlicht 27.02.2006 23:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query f...