Search CVE reports


Toggle filters

211 – 220 of 1060 results


CVE-2022-27378

Medium priority

Some fixes available 3 of 4

An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Fixed
mariadb-5.5
Show less packages

CVE-2022-27377

Medium priority

Some fixes available 3 of 4

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Fixed
mariadb-5.5
Show less packages

CVE-2022-27376

Medium priority

Some fixes available 3 of 4

MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5, mariadb-10.0

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Fixed
mariadb-5.5
mariadb-10.0
Show less packages

CVE-2022-24052

Medium priority

Some fixes available 2 of 4

MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2022-24051

Medium priority

Some fixes available 2 of 4

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2022-24050

Medium priority

Some fixes available 2 of 4

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...

6 affected packages

mariadb-10.6, mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.6 Not in release Not in release Not affected
mariadb-10.0
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-5.5
Show less packages

CVE-2022-24048

Medium priority

Some fixes available 2 of 4

MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Ignored
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2021-46322

Medium priority
Vulnerable

Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack.c.

14 affected packages

ceph, duktape, mariadb-10.0, mariadb-10.1, mariadb-10.3...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected Not affected Not affected Not affected Not affected
duktape Not affected Not affected Not affected Vulnerable Ignored
mariadb-10.0 Not in release Not in release Not in release Not in release Not in release
mariadb-10.1 Not in release Not in release Not in release Not in release Ignored
mariadb-10.3 Not in release Not in release Not in release Ignored Not in release
mariadb-10.5 Not in release Not in release
mariadb-5.5 Not in release Not in release Not in release Not in release Not in release
mysql-5.5 Not in release Not in release Not in release Not in release Not in release
mysql-5.6 Not in release Not in release Not in release Not in release Not in release
mysql-5.7 Not in release Not in release Not in release Not in release Not affected
mysql-8.0 Not in release Not affected Not affected Not affected Not in release
percona-server-5.6 Not in release Not in release Not in release Not in release Not in release
percona-xtradb-cluster-5.5 Not in release Not in release Not in release Not in release Not in release
percona-xtradb-cluster-5.6 Not in release Not in release Not in release Not in release Not in release
Show all 14 packages Show less packages

CVE-2022-21379

Medium priority

Some fixes available 8 of 11

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker...

12 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-5.5...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0 Not in release Not in release Not in release Not in release Not in release
mariadb-10.1 Not in release Not in release Not in release Not in release Not affected
mariadb-10.3 Not in release Not in release Not in release Not affected Not in release
mariadb-10.5 Not in release Not in release
mariadb-5.5 Not in release Not in release Not in release Not in release Not in release
mysql-5.5 Not in release Not in release Not in release Not in release Not in release
mysql-5.6 Not in release Not in release Not in release Not in release Not in release
mysql-5.7 Not in release Not in release Not in release Not in release Not affected
mysql-8.0 Not in release Fixed Fixed Fixed Not in release
percona-server-5.6 Not in release Not in release Not in release Not in release Not in release
percona-xtradb-cluster-5.5 Not in release Not in release Not in release Not in release Not in release
percona-xtradb-cluster-5.6 Not in release Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages

CVE-2022-21378

Medium priority

Some fixes available 8 of 11

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network...

12 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-5.5...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0 Not in release Not in release Not in release Not in release Not in release
mariadb-10.1 Not in release Not in release Not in release Not in release Not affected
mariadb-10.3 Not in release Not in release Not in release Not affected Not in release
mariadb-10.5 Not in release Not in release
mariadb-5.5 Not in release Not in release Not in release Not in release Not in release
mysql-5.5 Not in release Not in release Not in release Not in release Not in release
mysql-5.6 Not in release Not in release Not in release Not in release Not in release
mysql-5.7 Not in release Not in release Not in release Not in release Not affected
mysql-8.0 Not in release Fixed Fixed Fixed Not in release
percona-server-5.6 Not in release Not in release Not in release Not in release Not in release
percona-xtradb-cluster-5.5 Not in release Not in release Not in release Not in release Not in release
percona-xtradb-cluster-5.6 Not in release Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages