Mysql
Vendor:
First CVE: Sep 22, 2003 · Active for 22 years
95
Total CVEs
Bottom 1%
6.8
Avg CVEs / Year
Bottom 1%
4.7
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mysql over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2003
22 years ago
Most Recent CVE
Aug 12, 2019
2,539 days ago
CVE Severity & Scoring
Mysql95 CVEs
19%
68%
13%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (2.1%)
Network1 (1.1%)
Unknown92 (96.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (3.2%)
High0 (0.0%)
Unknown92 (96.8%)
User Interaction
None3 (3.2%)
Unknown92 (96.8%)
Required0 (0.0%)
Privileges Required
Low2 (2.1%)
High1 (1.1%)
None0 (0.0%)
Unknown92 (96.8%)
Top CVEs
Signals from CVEs in this product scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0226HIGH Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHel | Jan 10, 2008 | 7.5 | 84 | NO | YES |
CVE-2004-0627HIGH The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string. | Dec 6, 2004 | 10.0 | 78 | NO | YES |
CVE-2003-0780HIGH Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon | Sep 22, 2003 | 9.0 | 75 | NO | YES |
CVE-2004-0835HIGH MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER | Nov 3, 2004 | 7.5 | 46 | NO | YES |
CVE-2006-1518MEDIUM Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with | May 5, 2006 | 6.5 | 44 | NO | YES |
CVE-2009-2446HIGH Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause | Jul 13, 2009 | 8.5 | 41 | NO | YES |
CVE-2006-1516MEDIUM The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a usern | May 5, 2006 | 5.0 | 40 | NO | YES |
CVE-2006-4227MEDIUM MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote | Aug 18, 2006 | 6.5 | 37 | NO | YES |
CVE-2009-5026MEDIUM The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than | Aug 17, 2012 | 6.8 | 35 | NO | YES |
CVE-2006-3081MEDIUM mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to t | Jun 19, 2006 | 4.0 | 33 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (95 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.1% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
30.5% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (95 CVEs).
Media Mentions
Signals from CVEs in this product scope (95 CVEs).
Top CNAs Publishing CVEs For Mysql
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.9 | 2 | 5.0 | 6.0% | 0 | 1 |
| 6.0.10-bzr | 1 | 4.0 | 10.2% | 0 | 1 |
| 5.1.5 | 54 | 4.5 | 6.4% | 0 | 11 |
| 5.1.37 | 46 | 4.4 | 4.5% | 0 | 8 |
| 5.1.34 | 46 | 4.4 | 4.5% | 0 | 8 |
| 5.1.32 | 49 | 4.5 | 4.7% | 0 | 9 |
| 5.1.31 | 47 | 4.4 | 4.7% | 0 | 9 |
| 5.1.23 | 51 | 4.5 | 4.8% | 0 | 11 |
| 5.0.87 | 19 | 4.3 | 4.3% | 0 | 2 |
| 5.0.84 | 20 | 4.4 | 4.2% | 0 | 2 |
| 5.0.82 | 23 | 4.7 | 4.9% | 0 | 4 |
| 5.0.74 | 2 | 4.0 | 6.9% | 0 | 1 |
| 5.0.72 | 2 | 4.0 | 6.9% | 0 | 1 |
| 5.0.66 | 20 | 4.6 | 8.5% | 0 | 4 |
| 5.0.60 | 21 | 4.5 | 8.4% | 0 | 5 |
| 5.0.56 | 21 | 4.5 | 8.4% | 0 | 5 |
| 5.0.54 | 21 | 4.5 | 8.4% | 0 | 5 |
| 5.0.5.0.21 | 27 | 4.5 | 5.1% | 0 | 4 |
| 5.0.5 | 36 | 4.7 | 8.1% | 0 | 9 |
| 5.0.45b | 16 | 4.2 | 3.8% | 0 | 0 |