CVE-2004-0957
- EPSS 0.37%
- Veröffentlicht 09.02.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized...
- EPSS 1.05%
- Veröffentlicht 10.01.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
- EPSS 2.2%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.
CVE-2004-0835
- EPSS 4.57%
- Veröffentlicht 03.11.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauth...
- EPSS 3.61%
- Veröffentlicht 03.11.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length...
CVE-2004-0837
- EPSS 3.23%
- Veröffentlicht 03.11.2004 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
CVE-2004-0457
- EPSS 0.12%
- Veröffentlicht 28.09.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2004-0388
- EPSS 0.11%
- Veröffentlicht 01.06.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.
CVE-2004-0381
- EPSS 0.13%
- Veröffentlicht 04.05.2004 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.
- EPSS 1.86%
- Veröffentlicht 31.12.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.