CVE-2016-1249 is an out-of-bounds read vulnerability affecting the DBD::mysql Perl module prior to version 4.039, specifically when utilizing server-side prepared statements. An attacker can trigger a denial of service by manipulating the number of placeholders in WHERE conditions and output fields in SELECT expressions. This vulnerability has a CVSSv3 score of 5.9 (Medium), indicating a network-based attack with high impact on availability, but requiring high attack complexity. There is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.038_01CPE matchmatch criteria | cpe:2.3:a:dbd-mysql_project:dbd-mysql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.