Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown
CVE-2007-6313
Disclosure Date: February 18, 2008 (last updated October 04, 2023)
MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
0
Attacker Value
Unknown
CVE-2008-0226
Disclosure Date: January 10, 2008 (last updated October 04, 2023)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
0
Attacker Value
Unknown
CVE-2007-6303
Disclosure Date: December 10, 2007 (last updated October 04, 2023)
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
0
Attacker Value
Unknown
CVE-2007-6304
Disclosure Date: December 10, 2007 (last updated October 04, 2023)
The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
0
Attacker Value
Unknown
CVE-2007-5970
Disclosure Date: December 10, 2007 (last updated October 04, 2023)
MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
0
Attacker Value
Unknown
CVE-2007-2692
Disclosure Date: May 16, 2007 (last updated October 04, 2023)
The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
0
Attacker Value
Unknown
CVE-2007-2693
Disclosure Date: May 16, 2007 (last updated October 04, 2023)
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
0