Where
-Infinity
0
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

First published (updated )

Alexander:

Comments below.

Bruce -----

On 1/23/25 3:57 PM, Solar Designer wrote: Bruce,

Thank you very much for your reply. My reading of it is that Oracle is already doing a lot (publication in 3 formats) and isn't willing to do more (also separately send info pertaining to Oracle's Open Source projects to oss-security). Is that correct? If so, maybe someone external should start doing that... or someone from Oracle on one's own time... or people with the individual projects (e.g., someone involved in MySQL and someone involved in VirtualBox development)? Related to the last point/idea, I notice that the individual projects do not appear to include security/CVE info in their release announcements. For example, here are the recent ones for MySQL and VirtualBox with no mention of the security issues/fixes at all:

https://dev.mysql.com/doc/relnotes/mysql/9.2/en/news-9-2-0.html https://dev.mysql.com/doc/refman/9.2/en/mysql-nutshell.html

https://urldefense.com/v3/https://www.virtualbox.org/wiki/Changelog-7.1;!!ACWV5N9M2RV99hQ!OoHnj0vkzfVsOz2w-yZyUPGtE06u7mGHbIT6M3zp4jbsWBZ9jfxUG10LiMQUMRdy4vQckczaUtFCUc6rJp8$ https://urldefense.com/v3/https://www.virtualbox.org/wiki/Changelog-7.0;!!ACWV5N9M2RV99hQ!OoHnj0vkzfVsOz2w-yZyUPGtE06u7mGHbIT6M3zp4jbsWBZ9jfxUG10LiMQUMRdy4vQckczaUtFCYMzrXOJ$ https://www.oracle.com/security-alerts/cpujan2025.html in other dependent products. Maybe that's because the embargo end is coordinated centrally for the Critical Patch Update, and the projects end up never being given a green light to release the info on their own as well? Or just do not go back and add previously-suppressed change log entries? If so, could this be corrected? Just guessing here, I could as well be wrong about it. The embargo end is coordinated centrally, as you suspected. Bruce ----- Thanks again,

Alexander

On Thu, Jan 23, 2025 at 06:47:29AM -0800, Bruce Lowenthal wrote: Olle, Solar Designer, oss-security list:

I am responsible for the content and publication of Oracle Critical Patch Updates.   These are published quarterly in three formats: Tabular format HTML "AKA risk matrix", English Language HTML format and Oasis Standard CSAF format via references at Oracle's Critical Patch Updates, Security Alerts and Bulletins home page at

https://www.oracle.com/security-alerts/

This home page references individual quarterly reports and provides other information regarding our security program.   In addition, that page provides instructions allowing anyone to sign up to receive eMail announcing when Oracle Critical Patch Updates and other security advisories are published.    See:

Instructions for subscribing to email notifications <https://www.oracle.com/security-alerts/securityemail.html>of Critical Patch Update Advisories and Security Alerts.

If you have any questions, feel free to contact me directly.

Bruce -----

On 1/22/25 11:50 PM, Olle E. Johansson wrote: Bruce, For your information.

/O Begin forwarded message:

From: Solar Designer <solar () openwall com> Subject: [oss-security] Oracle January 2025 Critical Patch Update Date: 23 January 2025 at 03:42:22 CET To: oss-security () lists openwall com Reply-To: oss-security () lists openwall com

Hi,

Once in a while, Oracle publishes what they call Critical Patch Update documents, which list many vulnerabilities addressed across many Oracle products, some of them Open Source and some not.  This is great, but it would be even better if Oracle also communicated to oss-security about those vulnerabilities in its Open Source products, perhaps one message per product (e.g., MySQL separately from VirtualBox).  I hope someone from Oracle reads this and will get the wheels moving.  Anyone? Meanwhile, the latest Critical Patch Update is:

https://blogs.oracle.com/security/post/january-2025-cpu-released https://www.oracle.com/security-alerts/cpujan2025.html

For MySQL, it says:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL

"Oracle MySQL Risk Matrix

This Critical Patch Update contains 39 new security patches, plus additional third party patches noted below, for Oracle MySQL.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here."

and links to:

https://www.oracle.com/security-alerts/cpujan2025verbose.html#MSQL

and lists additional information on some CVEs not included in the matrix itself (duplicate or not vulnerable).  With so many CVEs, all of this is rather long, but I imagine someone from Oracle - or someone external - could copy-paste the "English text form of this Risk Matrix" and the extra notes on a few CVEs to a separate message focusing on MySQL.

Similarly, there's info on a couple of VirtualBox CVEs here, which would ideally be a separate message with copy-pasted detail:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixOVIR https://www.oracle.com/security-alerts/cpujan2025verbose.html#OVIR

Perhaps there's more Open Source software listed in there, which needs similar treatment.  Not only this time, but each time, please.

Alexander

First published (updated )

Hi Solar,

every quarter, I could do it after my initial reading!

Thank you,

Douglas Reno Linux From Scratch

On 1/23/25 5:57 PM, Solar Designer wrote: Bruce,

Thank you very much for your reply. My reading of it is that Oracle is already doing a lot (publication in 3 formats) and isn't willing to do more (also separately send info pertaining to Oracle's Open Source projects to oss-security). Is that correct?

If so, maybe someone external should start doing that... or someone from Oracle on one's own time... or people with the individual projects (e.g., someone involved in MySQL and someone involved in VirtualBox development)?

Related to the last point/idea, I notice that the individual projects do not appear to include security/CVE info in their release announcements. For example, here are the recent ones for MySQL and VirtualBox with no mention of the security issues/fixes at all:

https://dev.mysql.com/doc/relnotes/mysql/9.2/en/news-9-2-0.html https://dev.mysql.com/doc/refman/9.2/en/mysql-nutshell.html

https://www.virtualbox.org/wiki/Changelog-7.1 https://www.virtualbox.org/wiki/Changelog-7.0

Maybe that's because the embargo end is coordinated centrally for the Critical Patch Update, and the projects end up never being given a green light to release the info on their own as well? Or just do not go back and add previously-suppressed change log entries? If so, could this be corrected? Just guessing here, I could as well be wrong about it.

Thanks again,

Alexander

On Thu, Jan 23, 2025 at 06:47:29AM -0800, Bruce Lowenthal wrote: Olle, Solar Designer, oss-security list:

I am responsible for the content and publication of Oracle Critical Patch Updates.   These are published quarterly in three formats: Tabular format HTML "AKA risk matrix", English Language HTML format and Oasis Standard CSAF format via references at Oracle's Critical Patch Updates, Security Alerts and Bulletins home page at

https://www.oracle.com/security-alerts/

This home page references individual quarterly reports and provides other information regarding our security program.   In addition, that page provides instructions allowing anyone to sign up to receive eMail announcing when Oracle Critical Patch Updates and other security advisories are published.    See:

Instructions for subscribing to email notifications <https://www.oracle.com/security-alerts/securityemail.html>of Critical Patch Update Advisories and Security Alerts.

If you have any questions, feel free to contact me directly.

Bruce -----

On 1/22/25 11:50 PM, Olle E. Johansson wrote: Bruce, For your information.

/O Begin forwarded message:

From: Solar Designer <solar () openwall com> Subject: [oss-security] Oracle January 2025 Critical Patch Update Date: 23 January 2025 at 03:42:22 CET To: oss-security () lists openwall com Reply-To: oss-security () lists openwall com

Hi,

Once in a while, Oracle publishes what they call Critical Patch Update documents, which list many vulnerabilities addressed across many Oracle products, some of them Open Source and some not.  This is great, but it would be even better if Oracle also communicated to oss-security about those vulnerabilities in its Open Source products, perhaps one message per product (e.g., MySQL separately from VirtualBox).  I hope someone from Oracle reads this and will get the wheels moving.  Anyone? Meanwhile, the latest Critical Patch Update is:

https://blogs.oracle.com/security/post/january-2025-cpu-released https://www.oracle.com/security-alerts/cpujan2025.html

For MySQL, it says:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL

"Oracle MySQL Risk Matrix

This Critical Patch Update contains 39 new security patches, plus additional third party patches noted below, for Oracle MySQL.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here."

and links to:

https://www.oracle.com/security-alerts/cpujan2025verbose.html#MSQL

and lists additional information on some CVEs not included in the matrix itself (duplicate or not vulnerable).  With so many CVEs, all of this is rather long, but I imagine someone from Oracle - or someone external - could copy-paste the "English text form of this Risk Matrix" and the extra notes on a few CVEs to a separate message focusing on MySQL.

Similarly, there's info on a couple of VirtualBox CVEs here, which would ideally be a separate message with copy-pasted detail:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixOVIR https://www.oracle.com/security-alerts/cpujan2025verbose.html#OVIR

Perhaps there's more Open Source software listed in there, which needs similar treatment.  Not only this time, but each time, please.

Alexander

First published (updated )

Bruce,

Thank you very much for your reply. My reading of it is that Oracle is already doing a lot (publication in 3 formats) and isn't willing to do more (also separately send info pertaining to Oracle's Open Source projects to oss-security). Is that correct?

If so, maybe someone external should start doing that... or someone from Oracle on one's own time... or people with the individual projects (e.g., someone involved in MySQL and someone involved in VirtualBox development)?

Related to the last point/idea, I notice that the individual projects do not appear to include security/CVE info in their release announcements. For example, here are the recent ones for MySQL and VirtualBox with no mention of the security issues/fixes at all:

https://dev.mysql.com/doc/relnotes/mysql/9.2/en/news-9-2-0.html https://dev.mysql.com/doc/refman/9.2/en/mysql-nutshell.html

https://www.virtualbox.org/wiki/Changelog-7.1 https://www.virtualbox.org/wiki/Changelog-7.0

Maybe that's because the embargo end is coordinated centrally for the Critical Patch Update, and the projects end up never being given a green light to release the info on their own as well? Or just do not go back and add previously-suppressed change log entries? If so, could this be corrected? Just guessing here, I could as well be wrong about it.

Thanks again,

Alexander

On Thu, Jan 23, 2025 at 06:47:29AM -0800, Bruce Lowenthal wrote: Olle, Solar Designer, oss-security list:

I am responsible for the content and publication of Oracle Critical Patch Updates.   These are published quarterly in three formats: Tabular format HTML "AKA risk matrix", English Language HTML format and Oasis Standard CSAF format via references at Oracle's Critical Patch Updates, Security Alerts and Bulletins home page at

https://www.oracle.com/security-alerts/

This home page references individual quarterly reports and provides other information regarding our security program.   In addition, that page provides instructions allowing anyone to sign up to receive eMail announcing when Oracle Critical Patch Updates and other security advisories are published.    See:

Instructions for subscribing to email notifications <https://www.oracle.com/security-alerts/securityemail.html>of Critical Patch Update Advisories and Security Alerts.

If you have any questions, feel free to contact me directly.

Bruce -----

On 1/22/25 11:50 PM, Olle E. Johansson wrote: Bruce, For your information.

/O Begin forwarded message:

From: Solar Designer <solar () openwall com> Subject: [oss-security] Oracle January 2025 Critical Patch Update Date: 23 January 2025 at 03:42:22 CET To: oss-security () lists openwall com Reply-To: oss-security () lists openwall com

Hi,

Once in a while, Oracle publishes what they call Critical Patch Update documents, which list many vulnerabilities addressed across many Oracle products, some of them Open Source and some not.  This is great, but it would be even better if Oracle also communicated to oss-security about those vulnerabilities in its Open Source products, perhaps one message per product (e.g., MySQL separately from VirtualBox).  I hope someone from Oracle reads this and will get the wheels moving.  Anyone?

Meanwhile, the latest Critical Patch Update is:

https://blogs.oracle.com/security/post/january-2025-cpu-released https://www.oracle.com/security-alerts/cpujan2025.html

For MySQL, it says:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL

"Oracle MySQL Risk Matrix

This Critical Patch Update contains 39 new security patches, plus additional third party patches noted below, for Oracle MySQL.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here."

and links to:

https://www.oracle.com/security-alerts/cpujan2025verbose.html#MSQL

and lists additional information on some CVEs not included in the matrix itself (duplicate or not vulnerable).  With so many CVEs, all of this is rather long, but I imagine someone from Oracle - or someone external - could copy-paste the "English text form of this Risk Matrix" and the extra notes on a few CVEs to a separate message focusing on MySQL.

Similarly, there's info on a couple of VirtualBox CVEs here, which would ideally be a separate message with copy-pasted detail:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixOVIR https://www.oracle.com/security-alerts/cpujan2025verbose.html#OVIR

Perhaps there's more Open Source software listed in there, which needs similar treatment.  Not only this time, but each time, please.

Alexander

First published (updated )

Olle, Solar Designer, oss-security list: https://www.oracle.com/security-alerts/ Instructions for subscribing to email notifications <https://www.oracle.com/security-alerts/securityemail.html>of Critical Patch Update Advisories and Security Alerts.

If you have any questions, feel free to contact me directly.

Bruce -----

On 1/22/25 11:50 PM, Olle E. Johansson wrote: Bruce, For your information.

/O Begin forwarded message:

From: Solar Designer <solar () openwall com> Subject: [oss-security] Oracle January 2025 Critical Patch Update Date: 23 January 2025 at 03:42:22 CET To: oss-security () lists openwall com Reply-To: oss-security () lists openwall com

Hi,

Once in a while, Oracle publishes what they call Critical Patch Update documents, which list many vulnerabilities addressed across many Oracle products, some of them Open Source and some not.  This is great, but it would be even better if Oracle also communicated to oss-security about those vulnerabilities in its Open Source products, perhaps one message per product (e.g., MySQL separately from VirtualBox).  I hope someone from Oracle reads this and will get the wheels moving.  Anyone?

Meanwhile, the latest Critical Patch Update is:

https://blogs.oracle.com/security/post/january-2025-cpu-released https://www.oracle.com/security-alerts/cpujan2025.html

For MySQL, it says:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixMSQL

"Oracle MySQL Risk Matrix

This Critical Patch Update contains 39 new security patches, plus additional third party patches noted below, for Oracle MySQL.  4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.  The English text form of this Risk Matrix can be found here."

and links to:

https://www.oracle.com/security-alerts/cpujan2025verbose.html#MSQL

and lists additional information on some CVEs not included in the matrix itself (duplicate or not vulnerable).  With so many CVEs, all of this is rather long, but I imagine someone from Oracle - or someone external - could copy-paste the "English text form of this Risk Matrix" and the extra notes on a few CVEs to a separate message focusing on MySQL.

Similarly, there's info on a couple of VirtualBox CVEs here, which would ideally be a separate message with copy-pasted detail:

https://www.oracle.com/security-alerts/cpujan2025.html#AppendixOVIR https://www.oracle.com/security-alerts/cpujan2025verbose.html#OVIR

Perhaps there's more Open Source software listed in there, which needs similar treatment.  Not only this time, but each time, please.

Alexander

First published (updated )
Severity
1

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).

First published (updated )
Severity
4

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

First published (updated )
Severity
7

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

First published (updated )
Severity
4

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

First published (updated )
Severity
4

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

First published (updated )
Severity
4

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

First published (updated )
Severity
1

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).

First published (updated )
Severity
5.5
EPSS
0.04%
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

Last updated 30 January 2025

1 / 3
Source: Ubuntu
First published (updated )
Severity
5.5
EPSS
0.04%
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

Last updated 30 January 2025

1 / 3
Source: Ubuntu
First published (updated )
Severity
3.8
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Last updated 30 January 2025

1 / 3
Source: Ubuntu
First published (updated )
Severity
4.9
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Last updated 30 January 2025

1 / 3
Source: Ubuntu
First published (updated )
Severity
4.9
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Last updated 30 January 2025

1 / 3
Source: Ubuntu
First published (updated )
Severity
1

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).

First published (updated )
Severity
1

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).

First published (updated )
Severity
1

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

First published (updated )
Severity
7.5
SQL Injection
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

An unspecified vulnerability in Oracle MySQL Connectors related to the Connector/Python component could allow a remote authenticated attacker to cause high confidentiality high integrity and high availability impacts.

1 / 2
Source: IBM
First published (updated )
Severity
3.8
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data as well as unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).

1 / 2
Source: NVD
First published (updated )
Severity
2.2
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Last updated 12 November 2024

1 / 3
Source: Ubuntu
First published (updated )
Severity
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Last updated 12 November 2024

1 / 3
Source: Ubuntu
First published (updated )
Severity
2
Infoleak
AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 2.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.38 and prior, 8.4.1 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.4.0 and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Oracle MySQL Server is vulnerable to a denial of service related to the Server: Optimizer component. By sending a specially crafted request, a remote authenticated attacker could exploit this vulnerability to cause a denial of service.

1 / 2
Source: IBM
First published (updated )
Severity
4.9
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203