Search CVE reports
391 – 400 of 778 results
Some fixes available 3 of 6
MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.
6 affected packages
mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5, mariadb-10.0
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.1 | — | — | — | Needs evaluation |
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Fixed | — | — |
mariadb-5.5 | — | — | — | — |
mariadb-10.0 | — | — | — | — |
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
5 affected packages
rsync, zlib, mariadb-10.3, mariadb-10.6, klibc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
rsync | Not affected | Not affected | Fixed | Fixed |
zlib | Fixed | Fixed | Fixed | Fixed |
mariadb-10.3 | — | Not in release | Fixed | Not in release |
mariadb-10.6 | Not in release | Fixed | Not in release | Not in release |
klibc | Fixed | Fixed | Fixed | Fixed |
Some fixes available 2 of 6
MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...
6 affected packages
mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.0 | — | — | — | — |
mariadb-10.1 | — | — | — | Needs evaluation |
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Not affected | — | — |
mariadb-5.5 | — | — | — | — |
Some fixes available 2 of 6
MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...
6 affected packages
mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.0 | — | — | — | — |
mariadb-10.1 | — | — | — | Needs evaluation |
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Not affected | — | — |
mariadb-5.5 | — | — | — | — |
Some fixes available 2 of 6
MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...
6 affected packages
mariadb-10.0, mariadb-10.6, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.0 | — | — | — | — |
mariadb-10.6 | Not in release | Not affected | — | — |
mariadb-10.1 | — | — | — | Needs evaluation |
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-5.5 | — | — | — | — |
Some fixes available 2 of 6
MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...
6 affected packages
mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.0 | — | — | — | — |
mariadb-10.1 | — | — | — | Needs evaluation |
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Not affected | — | — |
mariadb-5.5 | — | — | — | — |
Some fixes available 3 of 4
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
3 affected packages
mariadb-10.6, mariadb-10.3, mariadb-10.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.6 | — | Fixed | — | — |
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
Some fixes available 3 of 5
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Fixed | — | — |
Some fixes available 1 of 4
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Not affected | — | — |
Some fixes available 2 of 4
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — |
mariadb-10.5 | — | — | — | — |
mariadb-10.6 | Not in release | Fixed | — | — |