Show filters
400 Total Results
Displaying 21-30 of 400
Sort by:
Attacker Value
Unknown

CVE-2022-31623

Disclosure Date: May 25, 2022 (last updated May 03, 2024)
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.
Attacker Value
Unknown

CVE-2022-31621

Disclosure Date: May 25, 2022 (last updated May 03, 2024)
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.
Attacker Value
Unknown

CVE-2022-31622

Disclosure Date: May 25, 2022 (last updated May 03, 2024)
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.
Attacker Value
Unknown

CVE-2022-21451

Disclosure Date: April 19, 2022 (last updated November 29, 2024)
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
0
Attacker Value
Unknown

CVE-2022-21427

Disclosure Date: April 19, 2022 (last updated November 29, 2024)
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
0
Attacker Value
Unknown

CVE-2022-27457

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.
Attacker Value
Unknown

CVE-2022-27456

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
Attacker Value
Unknown

CVE-2022-27455

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.
Attacker Value
Unknown

CVE-2022-27452

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
Attacker Value
Unknown

CVE-2022-27451

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.