Mysql

Vendor:

First CVE: Sep 22, 2003 · Active for 22 years

95
Total CVEs
Bottom 1%
6.8
Avg CVEs / Year
Bottom 1%
4.7
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mysql over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2003
22 years ago
Most Recent CVE
Aug 12, 2019
2,539 days ago

CVE Severity & Scoring

Mysql95 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local2 (2.1%)
Network1 (1.1%)
Unknown92 (96.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (3.2%)
High0 (0.0%)
Unknown92 (96.8%)
User Interaction
None3 (3.2%)
Unknown92 (96.8%)
Required0 (0.0%)
Privileges Required
Low2 (2.1%)
High1 (1.1%)
None0 (0.0%)
Unknown92 (96.8%)

Top CVEs

Signals from CVEs in this product scope (95 CVEs).

95 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHel
Jan 10, 20087.584NOYES
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
Dec 6, 200410.078NOYES
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon
Sep 22, 20039.075NOYES
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER
Nov 3, 20047.546NOYES
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with
May 5, 20066.544NOYES
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause
Jul 13, 20098.541NOYES
The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a usern
May 5, 20065.040NOYES
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote
Aug 18, 20066.537NOYES
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than
Aug 17, 20126.835NOYES
mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to t
Jun 19, 20064.033NOYES

Exploit Exposure

Signals from CVEs in this product scope (95 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.1% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
30.5% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (95 CVEs).

Media Mentions

Signals from CVEs in this product scope (95 CVEs).

Top CNAs Publishing CVEs For Mysql

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.0.925.06.0%01
6.0.10-bzr14.010.2%01
5.1.5544.56.4%011
5.1.37464.44.5%08
5.1.34464.44.5%08
5.1.32494.54.7%09
5.1.31474.44.7%09
5.1.23514.54.8%011
5.0.87194.34.3%02
5.0.84204.44.2%02
5.0.82234.74.9%04
5.0.7424.06.9%01
5.0.7224.06.9%01
5.0.66204.68.5%04
5.0.60214.58.4%05
5.0.56214.58.4%05
5.0.54214.58.4%05
5.0.5.0.21274.55.1%04
5.0.5364.78.1%09
5.0.45b164.23.8%00