Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-2008

29
FAUCET Score

CVE-2010-2008 is a denial-of-service vulnerability affecting MySQL versions prior to 5.1.48, including various distributions from Canonical, Fedora, and Oracle. Authenticated attackers with ALTER DATABASE privileges can crash the server and cause database loss by manipulating directory paths within an ALTER DATABASE command. The vulnerability has a CVSS score of 3.5, indicating a network-based attack with medium complexity and partial availability impact. While not listed in CISA's KEV catalog, an exploit is publicly available on ExploitDB, and it has garnered some community discussion, though no active exploitation or significant media coverage has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.1.48CPE matchmatch criteria
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
8.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
9.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*
10.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 2.0

3.5LOW

AV:N/AC:M/Au:S/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
SINGLE
Exploitability Score
6.8
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
9.01%
Probability of exploitation in next 30 days
EPSS Percentile
94.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-14537 · Aug 3, 2010
This CVE's current EPSS score of 0.0901 is in the 99th percentile among its peer group of 1,637 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2010-2008Moderate

mysql: remote authenticated DoS via ALTER DATABASE

Jul 6, 2010

References

bugs.mysql.com / bug.php
ExploitIssue TrackingVendor Advisory
dev.mysql.com / doc/refman/5.1/en/news-5-1-48.html
Broken Link
lists.fedoraproject.org / pipermail/package-announce/2010-July/044546.html
Third Party Advisory
secunia.com / advisories/40333
Third Party Advisory
secunia.com / advisories/40762
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11869
Third Party Advisory
mandriva.com / security/advisories
Broken Link
securityfocus.com / bid/41198
ExploitThird Party AdvisoryVDB Entry
securitytracker.com / id
ExploitThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-1017-1
Third Party Advisory
ubuntu.com / usn/USN-1397-1
Third Party Advisory
vupen.com / english/advisories/2010/1918
Permissions Required