Search CVE reports
91 – 100 of 263 results
CVE-2022-24051
Medium prioritySome fixes available 2 of 6
MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...
6 affected packages
mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.0 | — | — | — | — | Needs evaluation |
mariadb-10.1 | — | — | — | Needs evaluation | Ignored |
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Not affected | — | — | Ignored |
mariadb-5.5 | — | — | — | — | Ignored |
CVE-2022-24050
Medium prioritySome fixes available 2 of 6
MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...
6 affected packages
mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.0 | — | — | — | — | Needs evaluation |
mariadb-10.1 | — | — | — | Needs evaluation | Ignored |
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Not affected | — | — | Ignored |
mariadb-5.5 | — | — | — | — | Ignored |
CVE-2022-24048
Medium prioritySome fixes available 2 of 6
MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...
6 affected packages
mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.0 | — | — | — | — | Needs evaluation |
mariadb-10.1 | — | — | — | Needs evaluation | Ignored |
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Not affected | — | — | Ignored |
mariadb-5.5 | — | — | — | — | Ignored |
CVE-2021-46669
Low prioritySome fixes available 3 of 4
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | — | Fixed | — | — | Ignored |
CVE-2021-46668
Low prioritySome fixes available 3 of 5
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Fixed | — | — | Ignored |
CVE-2021-46667
Low prioritySome fixes available 1 of 4
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Not affected | — | — | Ignored |
CVE-2021-46666
Medium prioritySome fixes available 2 of 4
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Fixed | — | — | Ignored |
CVE-2021-46665
Low prioritySome fixes available 3 of 5
MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Fixed | — | — | Ignored |
CVE-2021-46664
Medium prioritySome fixes available 3 of 5
MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Fixed | — | — | Ignored |
CVE-2021-46663
Medium prioritySome fixes available 3 of 5
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
3 affected packages
mariadb-10.3, mariadb-10.5, mariadb-10.6
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
mariadb-10.3 | — | — | Fixed | — | Ignored |
mariadb-10.5 | — | — | — | — | Ignored |
mariadb-10.6 | Not in release | Fixed | — | — | Ignored |