CVE-2015-8949 is a critical use-after-free vulnerability in the my_login function of DBD::mysql versions prior to 4.033_01, affecting dbd-mysql_project and Debian Linux. This flaw allows attackers to achieve unspecified but potentially high impact (confidentiality, integrity, availability) by leveraging a call to mysql_errno after a failed my_login attempt. With a CVSS score of 9.8 (CRITICAL) and an EPSS percentile of 0.039, it is easily exploitable over the network with low attack complexity and no user interaction required. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and it's not in CISA KEV, the vulnerability has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.033CPE matchmatch criteria | cpe:2.3:a:dbd-mysql_project:dbd-mysql:4.033:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.