MariaDB's vulnerability footprint spans a modestly scoped but deeply embedded portfolio centered on its core relational database engine, connectors, and middleware components that serve a broad range of application stacks and deployment contexts. The recurring weakness classes across this portfolio—use-after-free conditions, SQL injection, improper locking, and code-injection flaws—reflect the memory-safety and query-processing complexity inherent to a large database system and its integration layers. Despite the substantial volume of disclosures, the vendor's exposure does not skew toward critical severity or widespread in-the-wild exploitation, allowing defenders to prioritize patch cycles based on deployment scope and network exposure rather than blanket urgency. Defenders should maintain awareness of updates across the database engine itself and its language-specific connectors, since application environments often embed multiple components from this vendor's stack. Current severity, exploitation activity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mariadb over time
Signals from CVEs in this vendor scope (420 CVEs).
420 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2122MEDIUM sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x | Jun 26, 2012 | 5.1 | 89 | NO | YES |
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2014-0195MEDIUM The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS Clie | Jun 5, 2014 | 6.8 | 80 | NO | YES |
CVE-2009-4484HIGH Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5 | Dec 30, 2009 | 7.5 | 79 | NO | YES |
CVE-2016-6662CRITICAL Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5. | Sep 20, 2016 | 9.8 | 78 | NO | YES |
CVE-2022-0778HIGH The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi | Mar 15, 2022 | 7.5 | 65 | NO | NO |
CVE-2014-0221MEDIUM The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (r | Jun 5, 2014 | 4.3 | 59 | NO | NO |
CVE-2012-5613MEDIUM MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative | Dec 3, 2012 | 6.0 | 58 | NO | YES |
CVE-2014-3470MEDIUM The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows | Jun 5, 2014 | 4.3 | 57 | NO | NO |
CVE-2018-25032HIGH zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 | 7.5 | 56 | NO | NO |
Signals from CVEs in this vendor scope (420 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mariadb.
Media articles that mention a CVE ID that affects a product developed by Mariadb — matched by CVE ID, not by vendor name.