CVE-2014-4258

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.

Published: 2014-07-17 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-4258 is rated Moderate Risk (59.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.48%). Core evidence: EPSS rose +2.89% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-4258

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.60% 3.48% +2.89%
2 2025-12-28 0.72% 0.60% -0.13%
3 2025-12-27 0.72%

Full EPSS history (16 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-4258

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.5 2.0 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.0 6.4 [email protected]

Weakness enumeration for CVE-2014-4258

OS Trackers for CVE-2014-4258

vendor priority summary link
redhat medium https://access.redhat.com/security/cve/CVE-2014-4258
ubuntu medium CVE-2014-4258 medium priority: Ubuntu including 4 source packages (mariadb-5.5, mysql-5.5, mysql-5.6, mysql-dfsg-5.1), 24 status rows across 6 suites (lucid, precise, saucy, trusty, upstream, utopic): DNE 11, released 6, needs-triage 3, not-affected 3, ignored 1. https://ubuntu.com/security/CVE-2014-4258

Affected software / configurations for CVE-2014-4258

Vendor Product Version Raw CPE
oracle mysql >= 5.5.0, <= 5.5.37 cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
oracle mysql >= 5.6.0, <= 5.6.17 cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
vmware vcenter_server_appliance 5.0 cpe:2.3:a:vmware:vcenter_server_appliance:5.0:*:*:*:*:*:*:*
vmware vcenter_server_appliance 5.0 cpe:2.3:a:vmware:vcenter_server_appliance:5.0:update_1:*:*:*:*:*:*
vmware vcenter_server_appliance 5.0 cpe:2.3:a:vmware:vcenter_server_appliance:5.0:update_2:*:*:*:*:*:*
vmware vcenter_server_appliance 5.1 cpe:2.3:a:vmware:vcenter_server_appliance:5.1:*:*:*:*:*:*:*
vmware vcenter_server_appliance 5.1 cpe:2.3:a:vmware:vcenter_server_appliance:5.1:update_1:*:*:*:*:*:*
vmware vcenter_server_appliance 5.1 cpe:2.3:a:vmware:vcenter_server_appliance:5.1:update_2:*:*:*:*:*:*
vmware vcenter_server_appliance 5.5 cpe:2.3:a:vmware:vcenter_server_appliance:5.5:*:*:*:*:*:*:*
vmware vcenter_server_appliance 5.5 cpe:2.3:a:vmware:vcenter_server_appliance:5.5:update_1:*:*:*:*:*:*
oracle solaris 11.3 cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
opensuse_project suse_linux_enterprise_desktop 11.0 cpe:2.3:o:opensuse_project:suse_linux_enterprise_desktop:11.0:sp3:*:*:*:*:*:*
opensuse_project suse_linux_enterprise_server 11.0 cpe:2.3:o:opensuse_project:suse_linux_enterprise_server:11.0:sp3:*:*:*:*:*:*
opensuse_project suse_linux_enterprise_server 11.0 cpe:2.3:o:opensuse_project:suse_linux_enterprise_server:11.0:sp3:*:*:*:vmware:*:*
opensuse_project suse_linux_enterprise_software_development_kit 11.0 cpe:2.3:o:opensuse_project:suse_linux_enterprise_software_development_kit:11.0:sp3:*:*:*:*:*:*
debian debian_linux 7.0 cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
mariadb mariadb >= 5.5.0, < 5.5.38 cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
mariadb mariadb >= 10.0.0, < 10.0.12 cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
suse linux_enterprise_desktop 11 cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
suse linux_enterprise_desktop 12 cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
suse linux_enterprise_server 11 cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
suse linux_enterprise_server 11 cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
suse linux_enterprise_server 12 cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
suse linux_enterprise_software_development_kit 11 cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*
suse linux_enterprise_software_development_kit 12 cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*
suse linux_enterprise_workstation_extension 12 cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:*:*:*:*:*:*:*

References for CVE-2014-4258

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2014-08/msg00012.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23 Mailing List Third Party Advisory
http://secunia.com/advisories/60425 Not Applicable
http://www.debian.org/security/2014/dsa-2985 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html Vendor Advisory
http://www.securityfocus.com/archive/1/534161/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/68564 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1030578 Broken Link Third Party Advisory VDB Entry
http://www.vmware.com/security/advisories/VMSA-2014-0012.html Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/94620 Third Party Advisory VDB Entry
cvelogic Threat Intelligence