Search CVE reports


Toggle filters

411 – 420 of 430 results


CVE-2022-27378

Medium priority

Some fixes available 3 of 5

An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Fixed
mariadb-5.5
Show less packages

CVE-2022-27377

Medium priority

Some fixes available 3 of 5

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Fixed
mariadb-5.5
Show less packages

CVE-2022-27376

Medium priority

Some fixes available 3 of 5

MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Fixed
mariadb-5.5
Show less packages

CVE-2018-25032

Medium priority
Fixed

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

5 affected packages

mariadb-10.3, mariadb-10.6, klibc, rsync, zlib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.3 Not in release Fixed Not in release
mariadb-10.6 Not in release Fixed Not in release Not in release
klibc Fixed Fixed Fixed Fixed
rsync Not affected Not affected Fixed Fixed
zlib Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-24052

Medium priority

Some fixes available 2 of 5

MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2022-24051

Medium priority

Some fixes available 2 of 5

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2022-24050

Medium priority

Some fixes available 2 of 5

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2022-24048

Medium priority

Some fixes available 2 of 5

MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to...

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.0
mariadb-10.1 Needs evaluation
mariadb-10.3 Fixed
mariadb-10.5
mariadb-10.6 Not in release Not in release Not affected
mariadb-5.5
Show less packages

CVE-2021-46669

Low priority

Some fixes available 3 of 4

MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

3 affected packages

mariadb-10.6, mariadb-10.5, mariadb-10.3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.6 Fixed
mariadb-10.5
mariadb-10.3 Fixed
Show less packages

CVE-2021-46668

Low priority

Some fixes available 3 of 5

MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.

3 affected packages

mariadb-10.6, mariadb-10.5, mariadb-10.3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mariadb-10.6 Not in release Fixed
mariadb-10.5
mariadb-10.3 Fixed
Show less packages