CVE-2006-3486 describes an off-by-one buffer overflow in the Instance Manager of MySQL versions before 5.0.23 and 5.1 before 5.1.12, potentially leading to a local denial of service (application crash). The vendor disputes its classification as a vulnerability, arguing that exploitation requires access levels that already permit disruption. With a CVSS score of 2.1 (AV:L/AC:L/Au:N/C:N/I:N/A:P), this vulnerability is considered low severity, requiring local access and resulting only in partial availability impact. There is no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating a very low exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.0CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:5.0.0:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:* | ||
5.0.2CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:* | ||
5.0.3CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:* | ||
5.0.4CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.