CVE-2025-30714
- EPSS 0.03%
- Veröffentlicht 15.04.2025 20:31:11
- Zuletzt bearbeitet 21.04.2025 20:17:53
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple pro...
CVE-2025-30706
- EPSS 0.09%
- Veröffentlicht 15.04.2025 20:31:08
- Zuletzt bearbeitet 21.04.2025 19:27:55
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocol...
CVE-2025-21548
- EPSS 0.07%
- Veröffentlicht 21.01.2025 21:15:21
- Zuletzt bearbeitet 18.06.2025 19:24:16
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple ...
CVE-2023-21971
- EPSS 0.12%
- Veröffentlicht 18.04.2023 20:15:16
- Zuletzt bearbeitet 21.11.2024 07:44:01
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pr...
CVE-2022-21824
- EPSS 0.4%
- Veröffentlicht 24.02.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:45:30
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, whi...
CVE-2021-44533
- EPSS 0.32%
- Veröffentlicht 24.02.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:10
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a m...
CVE-2021-44532
- EPSS 0.12%
- Veröffentlicht 24.02.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:10
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an inje...
CVE-2021-44531
- EPSS 0.08%
- Veröffentlicht 24.02.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:10
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting U...
- EPSS 0.28%
- Veröffentlicht 19.01.2022 12:15:15
- Zuletzt bearbeitet 21.11.2024 06:44:31
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pro...
CVE-2021-2471
- EPSS 62.75%
- Veröffentlicht 20.10.2021 11:16:17
- Zuletzt bearbeitet 21.11.2024 06:03:11
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple pro...