MySQL vulnerabilities
Showing 601 - 609 of 609 CVEs
- CVE-2001-0407 Published Jun 27, 2001
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
- CVE-2001-1454 Published Feb 9, 2001
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
- CVE-2001-1453 Published Feb 9, 2001
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
- CVE-2001-1274 Published Jan 23, 2001
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
- CVE-2001-1275 Published Jan 19, 2001
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
- CVE-2000-0981 Published Dec 19, 2000
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
- CVE-2000-0148 Published Feb 8, 2000
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
- CVE-2000-0045 Published Jan 11, 2000
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
- CVE-1999-1188 Published Dec 27, 1998
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.