Search CVE reports


Toggle filters

11 – 20 of 22 results


CVE-2021-43305

Medium priority

Some fixes available 1 of 4

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy...

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not affected Fixed
Show less packages

CVE-2021-43304

Medium priority
Ignored

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy...

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not affected
Show less packages

CVE-2021-42388

Medium priority

Some fixes available 1 of 4

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset...

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not affected Fixed
Show less packages

CVE-2021-42387

Medium priority

Some fixes available 1 of 4

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset...

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not affected Fixed
Show less packages

CVE-2020-26759

Medium priority
Ignored

clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow.

1 affected package

python-clickhouse-driver

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-clickhouse-driver Not affected Not in release Not in release
Show less packages

CVE-2019-16536

Medium priority
Needs evaluation

Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Needs evaluation Not in release Needs evaluation
Show less packages

CVE-2018-14672

Medium priority
Ignored

In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not in release Not affected Not in release
Show less packages

CVE-2018-14671

Medium priority
Ignored

In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not in release Not affected Not in release
Show less packages

CVE-2018-14670

Medium priority
Ignored

Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not in release Not affected Not in release
Show less packages

CVE-2018-14669

Medium priority
Ignored

ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.

1 affected package

clickhouse

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
clickhouse Not in release Not affected Not in release
Show less packages