CVE-2002-1376
- EPSS 4.12%
- Veröffentlicht 23.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and po...
CVE-2002-0969
- EPSS 0.09%
- Veröffentlicht 11.10.2002 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allo...
CVE-2001-1255
- EPSS 0.14%
- Veröffentlicht 02.10.2001 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
CVE-2001-0407
- EPSS 0.69%
- Veröffentlicht 27.06.2001 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
CVE-2001-1453
- EPSS 11.66%
- Veröffentlicht 09.02.2001 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
CVE-2001-1454
- EPSS 13.48%
- Veröffentlicht 09.02.2001 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
CVE-2001-1274
- EPSS 6.07%
- Veröffentlicht 23.01.2001 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
CVE-2001-1275
- EPSS 0.46%
- Veröffentlicht 19.01.2001 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
CVE-2000-0981
- EPSS 1.07%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
CVE-2000-0148
- EPSS 0.44%
- Veröffentlicht 08.02.2000 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.