CVE-2012-5612 describes a heap-based buffer overflow vulnerability in Oracle MySQL versions through 5.5.28 and MariaDB versions through 5.5.28a, affecting products from Canonical and SUSE. This flaw allows remote authenticated users to trigger a denial of service (memory corruption and crash) and potentially execute arbitrary code through various SQL commands. With a CVSS score of 6.5 (medium severity) and an EPSS score indicating high exploitability potential, the vulnerability has a network attack vector, low attack complexity, and can lead to partial confidentiality, integrity, and availability impacts. While not listed on the KEV catalog or Hot List, a Proof-of-Concept exploit is publicly available on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1.0, < 5.1.67CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 5.2.0, < 5.2.14CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 5.3.0, < 5.3.12CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 5.5.0, < 5.5.29CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
10.0.0CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.