CRITICAL9.8CVE-2016-9843The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving bi… >= 5.5.0, < 10.3.11-r0
>= 5.5.20, < 5.5.51-r0
CRITICAL9.1CVE-2026-44172MariaDB: mysql_real_escape_string() incorrectly handled big5 from 0, < 10.11.17-r0
CRITICAL9.0mariadb-10.3 - security update
>= 10.1.0, < 10.3.25-r0
HIGH8.8sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x be…
>= 10.2.0, < 10.1.32-r0
HIGH8.1mariadb-10.0 - security update
>= 5.5.20, < 5.5.51-r0
HIGH7.8MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability.
>= 10.2.0, < 10.4.24-r0
HIGH7.8MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability.
>= 10.2.0, < 10.4.24-r0
HIGH7.8MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability.
>= 10.2.0, < 10.4.24-r0
HIGH7.8MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability.
>= 10.2.0, < 10.4.24-r0
HIGH7.7mysql-5.5 - security update
>= 5.5.0, < 10.2.15-r0
HIGH7.7Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).
>= 5.5.0, < 10.1.23-r0
HIGH7.7Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).
>= 5.5.0, < 10.1.23-r0
HIGH7.5MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_i…
>= 10.3.0, < 10.5.17-r0
HIGH7.5MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
>= 10.4.0, < 10.5.17-r0
HIGH7.5MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
>= 10.3.0, < 10.5.17-r0
HIGH7.5MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
>= 10.5.0, < 10.5.17-r0
HIGH7.5MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0al…
>= 10.4.0, < 10.5.17-r0
HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Binary_string::free_buffer() at /sql/sql_stri…
from 0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.
>= 10.4.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
>= 10.3.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple…
>= 10.4.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
>= 10.3.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.
>= 10.4.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.
>= 10.4.0, < 10.4.25-r0
HIGH7.5There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
>= 10.3.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string…
>= 10.3.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.
>= 10.4.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.
>= 10.2.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.
>= 10.4.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via…
>= 10.2.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
>= 10.2.0, < 10.4.25-r0
HIGH7.5An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to…
>= 10.4.0, < 10.6.7-r0
HIGH7.5An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to ca…
>= 10.2.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via spec…
>= 10.2.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_f…
>= 10.4.0, < 10.4.25-r0
HIGH7.5An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Servi…
>= 10.2.0, < 10.4.25-r0
HIGH7.5An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of…
>= 10.2.0, < 10.4.25-r0
HIGH7.5An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause…
>= 10.3.0, < 10.4.25-r0
HIGH7.5An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial…
>= 10.2.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited v…
>= 10.2.0, < 10.4.25-r0
HIGH7.5MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via s…
>= 10.3.0, < 10.4.25-r0
HIGH7.5zlib - security update
>= 10.3.0, < 10.5.17-r0
HIGH7.5mysql-5.5 - security update
>= 10.0.0, < 10.1.22-r0
HIGH7.2mariadb-10.1 - security update
>= 10.2, < 10.3.28-r0
HIGH7.1Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.1.37-r0
HIGH7.1mysql-5.5 - security update
>= 5.5.0, < 10.1.32-r0
HIGH7.0With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an…
>= 10.2.0, < 10.3.27-r0
HIGH7.0mariadb-10.0 - security update
>= 5.5.0, < 10.1.21-r0
MEDIUM6.7Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging).
>= 5.5.0, < 10.1.21-r0
MEDIUM6.5mariadb-10.3 - security update
>= 10.3.0, < 10.6.13-r0
MEDIUM6.5mariadb-10.1 - security update
>= 10.1.0, < 10.3.27-r0
MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).
>= 5.5.0, < 10.3.20-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser).
>= 5.5.0, < 10.3.17-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML).
>= 5.5.0, < 10.3.17-r0
MEDIUM6.5mariadb-10.0 - security update
>= 5.5.0, < 10.1.38-r0
MEDIUM6.5mariadb-10.0 - security update
>= 10.0.0, < 10.3.11-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.3.11-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.3.11-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.2.0, < 10.1.37-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 5.5.0, < 10.2.15-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL).
>= 5.5.0, < 10.2.15-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.2.15-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.2.15-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).
>= 5.5.0, < 10.1.32-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).
>= 5.5.0, < 10.1.32-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).
>= 5.5.0, < 10.1.32-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL).
>= 5.5.0, < 10.1.32-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.1.32-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).
>= 5.5.0, < 10.1.32-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).
>= 5.5.0, < 10.1.23-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL).
>= 5.5.0, < 10.1.21-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB).
>= 10.0.0, < 10.1.21-r0
MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).
>= 5.5.0, < 10.1.21-r0
MEDIUM6.5mysql-5.5 - security update
>= 5.5.0, < 10.1.21-r0
MEDIUM6.5Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x…
>= 5.5.20, < 5.5.51-r0
MEDIUM6.3Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging).
>= 5.5.0, < 10.1.21-r0
MEDIUM5.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).
>= 10.2.0, < 10.4.21-r0
MEDIUM5.9Vulnerability in the MySQL Client product of Oracle MySQL (component: C API).
>= 5.5.0, < 10.3.22-r0
MEDIUM5.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs).
>= 5.5.0, < 10.2.15-r0
MEDIUM5.6Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging).
>= 5.5.0, < 10.1.21-r0
MEDIUM5.5MariaDB Server before 10.7 is vulnerable to Denial of Service.
>= 10.3.0, < 10.6.7-r0
MEDIUM5.5MariaDB Server before 10.7 is vulnerable to Denial of Service.
>= 10.3.0, < 10.6.7-r0
MEDIUM5.5MariaDB Server before 10.7 is vulnerable to Denial of Service.
>= 10.3.0, < 10.6.7-r0
MEDIUM5.5MariaDB Server before 10.7 is vulnerable to Denial of Service.
>= 10.3.0, < 10.6.7-r0
MEDIUM5.5MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine…
>= 10.2.0, < 10.4.24-r0
MEDIUM5.5MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
>= 10.3.0, < 10.6.7-r0
MEDIUM5.5MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
>= 10.2.0, < 10.4.24-r0
MEDIUM5.5MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
>= 10.2.0, < 10.4.24-r0
MEDIUM5.5MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
>= 10.2.41, < 10.4.24-r0
MEDIUM5.5MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.
>= 10.3.0, < 10.6.7-r0
MEDIUM5.5MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CT…
>= 10.2.0, < 10.4.24-r0
MEDIUM5.5MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
>= 5.5.0, < 10.4.24-r0
MEDIUM5.5Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).
>= 10.2.0, < 10.4.22-r0
MEDIUM5.5Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).
>= 10.2.0, < 10.3.23-r0
MEDIUM5.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.2.0, < 10.3.17-r0
MEDIUM5.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.2.0, < 10.3.11-r0
MEDIUM5.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.0.0, < 10.2.15-r0
MEDIUM5.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).
>= 10.2.0, < 10.2.15-r0
MEDIUM5.5Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x…
>= 5.5.20, < 5.5.51-r0