Show filters
58 Total Results
Displaying 41-50 of 58
Sort by:
Attacker Value
Unknown

CVE-2010-3682

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
0
Attacker Value
Unknown

CVE-2010-3676

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (1) innodb_file_format or (2) innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement.
0
Attacker Value
Unknown

CVE-2010-3678

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
0
Attacker Value
Unknown

CVE-2010-3681

Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
0
Attacker Value
Unknown

CVE-2010-1850

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.
0
Attacker Value
Unknown

CVE-2010-1848

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.
0
Attacker Value
Unknown

CVE-2010-1849

Disclosure Date: June 08, 2010 (last updated October 04, 2023)
The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
0
Attacker Value
Unknown

CVE-2010-1626

Disclosure Date: May 21, 2010 (last updated October 04, 2023)
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
0
Attacker Value
Unknown

CVE-2009-4019

Disclosure Date: November 30, 2009 (last updated October 04, 2023)
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
0
Attacker Value
Unknown

CVE-2009-4028

Disclosure Date: November 30, 2009 (last updated October 04, 2023)
The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library.
0