Oracle

Mysql Server

260 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 19.04.2022 21:15:14
  • Last modified 21.11.2024 06:44:38

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple pro...

  • EPSS 0.15%
  • Published 19.04.2022 21:15:14
  • Last modified 21.11.2024 06:44:38

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple p...

  • EPSS 0.15%
  • Published 19.04.2022 21:15:14
  • Last modified 21.11.2024 06:44:39

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to...

  • EPSS 0.11%
  • Published 19.04.2022 21:15:14
  • Last modified 21.11.2024 06:44:40

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c...

  • EPSS 0.4%
  • Published 24.02.2022 19:15:10
  • Last modified 21.11.2024 06:45:30

Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, whi...

  • EPSS 0.08%
  • Published 24.02.2022 19:15:09
  • Last modified 21.11.2024 06:31:10

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting U...

Exploit
  • EPSS 0.12%
  • Published 24.02.2022 19:15:09
  • Last modified 21.11.2024 06:31:10

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an inje...

Exploit
  • EPSS 0.32%
  • Published 24.02.2022 19:15:09
  • Last modified 21.11.2024 06:31:10

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a m...

  • EPSS 0.15%
  • Published 19.01.2022 12:15:16
  • Last modified 21.11.2024 06:44:33

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access v...

  • EPSS 5.05%
  • Published 19.01.2022 12:15:16
  • Last modified 21.11.2024 06:44:34

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.34 and prior, 7.5.24 and prior, 7.6.20 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows hi...